Report a security issue
How to privately report a suspected security issue to The Wo.
If you believe you have found a security issue in The Wo, contact
security@thewo.io. This is the intended security
reporting address. Mailbox activation and delivery have not yet been verified,
so do not assume that it is monitored until this page is updated after an
operator confirms the production mail route.
Appropriate reports include a suspected vulnerability, an exposed customer API
key, a credential compromise, suspicious authentication behavior, or
unintended data exposure.
Please report privately. Do not post sensitive findings in public GitHub
issues, discussions, status updates, or ordinary support threads. Do not send
passwords, raw API keys, access tokens, recovery codes, MFA codes, private keys,
unrelated secrets, or full customer datasets. If a credential may be exposed,
describe its type and affected environment without including its value.
Useful non-secret context includes the affected product or endpoint, concise
reproduction steps, observed impact, safe timestamps, and a request or
reference identifier when appropriate. The Wo may ask for additional safe
information during triage.
Reports are reviewed and triaged. The Wo does not offer a bug bounty or other
reporting reward, and this page does not promise response times, remediation
deadlines, legal safe harbor, or a breach determination.
