Disclosure Policy
CAW is committed to transparency in how we identify, handle, and disclose security vulnerabilities and material information. This policy outlines our responsible disclosure practices.
1. Scope
This Disclosure Policy applies to all products, services, websites, and systems operated by CAW Solutions ("we", "our" or "the studio"). It describes how security researchers and third parties can responsibly report potential vulnerabilities and how we handle the disclosure of relevant information.
2. Responsible Disclosure
We encourage the responsible disclosure of security vulnerabilities. If you believe you have found a security issue in any of our systems, please report it to us privately before disclosing it publicly, giving us reasonable time to investigate and remediate the issue.
3. How to Report
To report a vulnerability or security concern, please email us at [email protected] with a detailed description. Please include:
- A clear description of the vulnerability;
- Steps to reproduce the issue;
- The potential impact of the vulnerability;
- Any supporting materials, such as logs or screenshots.
4. Our Commitment
Upon receiving a report, we will acknowledge it in a timely manner, investigate the issue, and keep you informed of our progress. We are committed to resolving verified vulnerabilities as quickly as possible and to acting in good faith toward researchers who follow this policy.
5. Guidelines for Researchers
We ask that researchers avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data. Please only interact with accounts you own or have explicit permission to access.
6. Changes to This Policy
We may update this Disclosure Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "last updated" date.