Disclosure Policy

CAW is committed to transparency in how we identify, handle, and disclose security vulnerabilities and material information. This policy outlines our responsible disclosure practices.

1. Scope

This Disclosure Policy applies to all products, services, websites, and systems operated by CAW Solutions ("we", "our" or "the studio"). It describes how security researchers and third parties can responsibly report potential vulnerabilities and how we handle the disclosure of relevant information.

2. Responsible Disclosure

We encourage the responsible disclosure of security vulnerabilities. If you believe you have found a security issue in any of our systems, please report it to us privately before disclosing it publicly, giving us reasonable time to investigate and remediate the issue.

3. How to Report

To report a vulnerability or security concern, please email us at [email protected] with a detailed description. Please include:

  • A clear description of the vulnerability;
  • Steps to reproduce the issue;
  • The potential impact of the vulnerability;
  • Any supporting materials, such as logs or screenshots.

4. Our Commitment

Upon receiving a report, we will acknowledge it in a timely manner, investigate the issue, and keep you informed of our progress. We are committed to resolving verified vulnerabilities as quickly as possible and to acting in good faith toward researchers who follow this policy.

5. Guidelines for Researchers

We ask that researchers avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data. Please only interact with accounts you own or have explicit permission to access.

6. Changes to This Policy

We may update this Disclosure Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "last updated" date.

Last updated: March 1, 2026