Digital Worker
Resolution Center

Security & Responsible Disclosure

Security & Responsible Disclosure

How to tell us if you find a security problem with this publication.

Version
1.0
Effective
16 September 2026
Last updated
16 September 2026
Status
Establishment-stage policy β€” legal review pending

What this covers

This concerns DWRC's public institutional website. That surface is deliberately small: it is a published site with no accounts, no sign-in, no forms, no database, and no application programming interface. There is no case system, because DWRC does not yet operate one.

Reporting a concern

If you believe you have found a security problem, please write to [email protected] with enough detail to reproduce it. DWRC does not currently operate a dedicated security address; when one is established, this document will be updated. Please do not include confidential third-party data in your report.

What to expect

Reports are read and taken seriously. DWRC does not operate a bug bounty, does not offer payment, has no published response-time commitment, and runs no continuous security programme or formal certification β€” stating otherwise would be untrue at this stage. DWRC also cannot offer a legal safe harbour for security testing, because that requires legal review that has not taken place.

Please test conservatively

If you are investigating, please stay within what is necessary to demonstrate a problem: no denial-of-service, no attempts to degrade the service for others, and no access to data that is not yours. Nothing here grants authorization to attack DWRC systems or the infrastructure that serves them.

Contact

Questions about this document may be sent to [email protected].

Legal, Trust & Governance