WebDisk

Vulnerability Disclosure Policy

We take the security of our services seriously and we value the work of researchers who help us improve it. This document explains how to report a vulnerability to us and what you can expect in return.

How to report

Send reports to security@webdisk.io. The same address is published in our security.txt file (RFC 9116) on webdisk.io and webdisk.pl.

Please include enough detail to reproduce the issue: the URL or component, reproduction steps, the observed impact and, where possible, your own assessment of severity. We read Polish and English.

We do not currently publish a PGP key. If your report contains sensitive data, say so in your first message and we will agree on a secure channel.

Scope

This policy covers the services and domains we operate, in particular:

Out of scope

Customer services and customer data hosted on products they bought from us are out of scope — we are not entitled to authorise testing against other people's data. Third-party systems we rely on are also out of scope, even when they run under one of our subdomains.

Rules of engagement

Please act in good faith and keep risk to our customers to a minimum. In practice:

What you can expect from us

We will acknowledge your report within 5 business days. Within 15 business days we will give you an initial assessment and tell you whether we treat the issue as a vulnerability. We will keep you updated at reasonable intervals until the case is closed.

Our default coordinated disclosure window is 90 days from acknowledgement. If we need longer, we will say so and explain why. We are happy to credit you as the reporter if you would like that.

Safe harbour

If you act in accordance with this policy, in good faith and without intent to cause harm, we will not bring civil claims against you or initiate criminal proceedings in relation to the research itself. We will also treat your activity as authorised should anyone question it on our side.

One limitation: we cannot waive liability towards third parties or state authorities. Where research touches our customers’ data or systems, this protection does not extend to claims brought by those customers.

Rewards

We do not run a bug bounty programme and we do not pay monetary rewards. That does not make your report any less welcome — we take every well-founded submission seriously.


Last updated: 1 August 2026