Security and Vulnerability Disclosure
Last updated: September 26, 2026
We sell security analysis, so we hold ourselves to the standard we recommend. If you think you have found a vulnerability in TestersWiz, please tell us. This page explains how, and what you can expect from us.
1. How to report
Email [email protected] with Security report in the subject. Please include what you found, where, the steps to reproduce it, and its likely impact. Do not include other people's personal data; describe it instead.
2. Scope
In scope: the TestersWiz website and application on our own domain, its API routes, and the App Security Check and Database Security Audit.
Out of scope: services run by others (for example Google, Supabase, Stripe, Vercel, Amazon Web Services, Resend, Anthropic), which have their own disclosure programmes; denial-of-service or load testing; social engineering, phishing or physical attacks; spam; reports from automated scanners without a demonstrated impact; and missing best-practice headers with no exploitable consequence.
3. Rules for good-faith research
- Use only accounts you own, or test accounts you create for the purpose.
- Do not access, change, delete or keep other users' data. If you reach personal data by accident, stop, do not copy it, and tell us straight away.
- Do not degrade the Service for anyone: no denial-of-service, no high-volume automated scanning, and respect rate limits.
- Do not use our security tools to analyse apps or databases that are not yours, and do not attempt to escape or extract data from the analysis environment beyond what is needed to show the issue.
- Give us a reasonable time to fix the issue before telling anyone else — we ask for 90 days, or less if we have fixed it sooner — and agree the timing with us.
- Do not demand payment in return for not disclosing an issue.
4. Our commitment to you
If you act in good faith and follow the rules above, we will not bring legal action against you, or ask anyone to, for your research — including under computer misuse or anti-circumvention laws — and we will treat your activity as authorised by us. If a third party brings action against you for activity that followed this policy, we will make it known that it was authorised. We cannot authorise testing of systems that belong to others.
We will:
- acknowledge your report within five business days;
- keep you updated while we investigate and fix it;
- tell you when it is fixed; and
- credit you publicly if you would like, once it is fixed.
We do not currently run a paid bug bounty.
5. More
How we protect data is summarised in the Privacy Policy. This policy is also published at /.well-known/security.txt.