Vulnerability Disclosure Policy
We take the security of our services seriously and we value the work of researchers who help us improve it. This document explains how to report a vulnerability to us and what you can expect in return.
How to report
Send reports to security@webdisk.io. The same address is published in our security.txt file (RFC 9116) on webdisk.io and webdisk.pl.
Please include enough detail to reproduce the issue: the URL or component, reproduction steps, the observed impact and, where possible, your own assessment of severity. We read Polish and English.
We do not currently publish a PGP key. If your report contains sensitive data, say so in your first message and we will agree on a secure channel.
Scope
This policy covers the services and domains we operate, in particular:
- webdisk.pl, webdisk.io and their subdomains
- WebDisk panels and applications (including Files, Send, Next, VM, Cloud)
- public infrastructure served from our IP ranges
Out of scope
Customer services and customer data hosted on products they bought from us are out of scope — we are not entitled to authorise testing against other people's data. Third-party systems we rely on are also out of scope, even when they run under one of our subdomains.
- denial of service (DoS/DDoS) and volumetric testing
- social engineering of our staff, customers or suppliers
- physical testing of facilities or hardware
- spam, mass account registration, form flooding
- automated scanner output without a demonstrated, exploitable impact
- missing best practices with no demonstrated impact (e.g. header configuration alone)
Rules of engagement
Please act in good faith and keep risk to our customers to a minimum. In practice:
- use only your own accounts and test data
- do not access, modify or delete data belonging to others — if you encounter personal data, stop and tell us
- do not degrade the availability or integrity of the services
- do not retain access longer than needed to demonstrate the issue, and remove anything you leave behind
- do not disclose the issue publicly before we have agreed a timeline
What you can expect from us
We will acknowledge your report within 5 business days. Within 15 business days we will give you an initial assessment and tell you whether we treat the issue as a vulnerability. We will keep you updated at reasonable intervals until the case is closed.
Our default coordinated disclosure window is 90 days from acknowledgement. If we need longer, we will say so and explain why. We are happy to credit you as the reporter if you would like that.
Safe harbour
If you act in accordance with this policy, in good faith and without intent to cause harm, we will not bring civil claims against you or initiate criminal proceedings in relation to the research itself. We will also treat your activity as authorised should anyone question it on our side.
One limitation: we cannot waive liability towards third parties or state authorities. Where research touches our customers’ data or systems, this protection does not extend to claims brought by those customers.
Rewards
We do not run a bug bounty programme and we do not pay monetary rewards. That does not make your report any less welcome — we take every well-founded submission seriously.
Last updated: 1 August 2026