Wirtor Trust Centre

Security & Vulnerability Disclosure

We welcome good-faith reports that help us identify and remediate security weaknesses before they cause harm.

Effective: 25 July 2026

Trust & policies

Trust CentrePrivacy PolicyCookie PolicyTerms of UseAcceptable UseSecurity & DisclosureResponsible AIAccessibility

1. Security approach

Wirtor applies a risk-based, defence-in-depth approach appropriate to the maturity and nature of its services. Our programme is intended to develop around secure design, least privilege, controlled change, encryption, logging, dependency management, backups, incident response, supplier assurance and regular review.

No organisation can guarantee absolute security. We prioritise credible risks based on likely impact, exploitability, affected users and evidence of active exploitation.

2. How to report a vulnerability

Email [email protected] with the subject line Security vulnerability report.

Please include, where possible:

  • the affected domain, page, endpoint, component or version;
  • a clear description of the issue and potential impact;
  • reproducible steps, proof-of-concept material or relevant logs;
  • the date and time of testing and any IP address used;
  • whether personal information or customer data may be affected;
  • your preferred contact details and disclosure expectations.

Do not include unnecessary personal data, secrets or complete data extracts. Use redaction wherever possible.

3. Good-faith research conditions

To remain within this policy, you must:

  • act to avoid privacy violations, service disruption and harm;
  • test only what is necessary to demonstrate the issue;
  • stop immediately if you access non-public data or affect other users;
  • not alter, download, retain, disclose or destroy data;
  • not use denial-of-service, social engineering, phishing, spam, malware or physical intrusion;
  • not test third-party systems unless they are expressly in scope;
  • give us a reasonable opportunity to investigate and remediate before public disclosure;
  • comply with applicable law.

4. Scope

Unless we publish a more specific scope, reports concerning Wirtor-controlled internet-facing services under wirtor.com are eligible for review. Customer-managed environments, third-party services, social media accounts and issues requiring physical access are out of scope unless expressly authorised.

5. Our response

We aim to acknowledge a credible report within five working days, validate and prioritise it, maintain reasonable communication, and coordinate remediation and disclosure where appropriate. These are targets rather than contractual service levels.

6. Safe-harbour statement

Where you make a genuine effort to comply with this policy, act in good faith and avoid harm, Wirtor does not intend to initiate legal action solely because of your authorised security research. This statement does not bind third parties or excuse unlawful conduct.

7. Rewards and recognition

Wirtor does not currently operate a paid bug-bounty programme. Recognition may be offered at our discretion and only with the reporter’s consent.