WebDefect
RFC 9116 & ISO 29147 VULNERABILITY POLICY

Responsible Disclosure & Security Safe Harbor

At WebDefect, we prioritize infrastructure integrity and customer safety. If you believe you have discovered a potential security vulnerability, we invite you to report it to our security operations team in accordance with this disclosure standard.

LEGAL SAFE HARBOR

Our Safe Harbor Commitment

If you conduct vulnerability research in good faith and adhere strictly to these guidelines, we will not initiate legal action against you, nor will we pursue law enforcement complaints related to your authorized research activities. We view security researchers as indispensable partners in maintaining Internet defense.

Assessment Scope

In Scope

  • webdefect.com and all direct subdomains
  • The external scanning core and public API endpoints
  • User authentication, session tokens, and customer account portals
  • Report generation pipelines and export artifacts

Out of Scope (Strictly Prohibited)

  • Denial of Service (DoS/DDoS) attacks against our infrastructure or scanned targets
  • Social engineering, phishing, or physical attacks against employees
  • Destruction, exfiltration, or modification of user or target data
  • Third-party cloud infrastructure and CDN providers (e.g. AWS, Cloudflare)

Submission Protocol & Response SLA

To report an issue, transmit your findings via encrypted email to:

security@webdefect.com

Please include in your report:

  • Clear summary of the vulnerability, potential CVSS impact, and affected endpoint(s)
  • Reproducible step-by-step instructions or cURL proof-of-concept (PoC)
  • Recommendations for containment or remediation
  • Your name or handle if you wish to be acknowledged in our security hall of fame
Initial Response: < 24 business hours
Triage & Validation: < 72 business hours
Remediation Status Updates: Every 7 calendar days

PGP Public Key

Encrypt sensitive vulnerability reports to our security team using this PGP key. Key ID: 0xBD7A2F8C4E1D9B3A · Fingerprint: A1B2 C3D4 E5F6 7890 1234 5678 BD7A 2F8C 4E1D 9B3A

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGX4kpsBEAC7vN2Q8mZ3pKlRtY9uXwDfGhJnMsA+oPqBiVcLe6TdFkW1
Hy3RmQzNpUoX8sSbIcPvEjYkAl5tGwDqMfZnXrVuBoCdKhLgSmTiEaNe2yFP
JdRbOcHvWpKxQlUsTmYeNfZkIoXrDgAuBhSvCwPjElMqTnYoVfZsRuBkAoXd
LhGnPmKrSwQvYbIcFjNtEdZuOaWpMxKlRgVnCsHqBiJyPeDfTkXmNwZoUvAs
FbGcHdIeJfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGcHdIe
JfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGcHdIeJfKgLhMi
NjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGcHdIeJfKgLhMiNjOkPlQm
RnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGcHdIeJfKgLhMiNjOkPlQmRnSoTpUq
VrWsXtYuZvAwBxCyDzEaFbGcHdIeJfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYu
ZvAwBxCyDzEaFbGcHdIeJfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCy
DzEaFbGcHdIeJfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGc
HdIeJfKgLhMiNjOkPlQmRnSoTpUqVrWsXtYuZvAwBxCyDzEaFbGcHdIeJfKg
wEbCzDnEoFpGqHrIsJtKuLvMwNxOyPzQaRbScTdUeVfWgXhYiZjAkBlCmDnEo
FpGqHrIsJtKuLvMwNxOyPzQaRbScTdUeVfWgXhYiZjAkBlCmDnEoFpGqHrIs
JtKuLvMwNxOyPzQaRbScTdUeVfWgXhYiZjAkBlCmDnEoFpGqHrIsJtKuLvMw
NxOyPzQaRbScTdUeVfWgXhYiZjAkBlCmDnEo=
=mNpQ
-----END PGP PUBLIC KEY BLOCK-----

You can also retrieve this key from keys.openpgp.org by searching for security@webdefect.com