Security & Responsible Disclosure
Security & Responsible Disclosure
How to tell us if you find a security problem with this publication.
- Version
- 1.0
- Effective
- 16 September 2026
- Last updated
- 16 September 2026
- Status
- Establishment-stage policy β legal review pending
What this covers
This concerns DWRC's public institutional website. That surface is deliberately small: it is a published site with no accounts, no sign-in, no forms, no database, and no application programming interface. There is no case system, because DWRC does not yet operate one.
Reporting a concern
If you believe you have found a security problem, please write to [email protected] with enough detail to reproduce it. DWRC does not currently operate a dedicated security address; when one is established, this document will be updated. Please do not include confidential third-party data in your report.
What to expect
Reports are read and taken seriously. DWRC does not operate a bug bounty, does not offer payment, has no published response-time commitment, and runs no continuous security programme or formal certification β stating otherwise would be untrue at this stage. DWRC also cannot offer a legal safe harbour for security testing, because that requires legal review that has not taken place.
Please test conservatively
If you are investigating, please stay within what is necessary to demonstrate a problem: no denial-of-service, no attempts to degrade the service for others, and no access to data that is not yours. Nothing here grants authorization to attack DWRC systems or the infrastructure that serves them.
Contact
Questions about this document may be sent to [email protected].