Vulnerability Disclosure Policy

Wu Wo Partnership Limited | Effective Date: January 2025

At Wu Wo Partnership Limited, we take the security and privacy of our systems, applications, and customer data seriously. We welcome contributions from security researchers, clients, and independent third parties to help us maintain a secure environment.

This policy outlines our guidelines for responsibly discovering and reporting security vulnerabilities in our software and web applications.

1. How to Report a Vulnerability

If you believe you have discovered a security vulnerability in any application or web service operated by Wu Wo Partnership Limited, please report it to us as soon as possible.

Security Email: support+security@wu-wo.co.uk

Security Manifest (RFC 9116): https://wu-wo.co.uk/.well-known/security.txt

What to Include in Your Report: To help us triage and validate the issue efficiently, please include:

  • A summary of the suspected vulnerability and its potential security impact.
  • Clear, step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
  • The specific application domain, URL, or API route affected.
  • Your contact information if you would like us to follow up with you.

2. Our Response Commitments

When you report an issue to us following this policy, we commit to the following response timeline:

  • Initial Acknowledgment: We will acknowledge receipt of your report within 24 to 48 hours.
  • Triage & Risk Assessment: We will assess and confirm the validity of the report within 3 business days.
  • Remediation & Patching: We aim to resolve and deploy fixes for verified Critical and High-severity vulnerabilities within 14 calendar days, depending on operational complexity.
  • Communication: We will keep you informed of our progress as we work to resolve the issue.

3. Safe Harbor & Research Guidelines

We consider security research conducted in good faith to be authorized and beneficial. If you comply with the following guidelines during your research, we will not pursue legal action or refer matters to law enforcement:

  • Respect Data Integrity: Do not view, download, modify, or destroy data belonging to other users or clients.
  • Avoid Service Disruption: Do not perform Denial of Service (DoS/DDoS) attacks, automated spamming, or high-volume brute-force attacks that impair application performance.
  • Responsible Disclosure: Give us a reasonable amount of time to address and patch the vulnerability before making details public.
  • Social Engineering: Do not execute social engineering attacks, phishing campaigns, or physical security testing against Wu Wo staff or infrastructure.

4. Scope

This policy applies to all web applications, APIs, and cloud services owned and operated by Wu Wo Partnership Limited.

Third-party services or infrastructure hosted independently by external providers (e.g., AWS core infrastructure, external SaaS tools) are subject to those respective providers' disclosure policies.