At Wu Wo Partnership Limited, we take the security and privacy of our systems, applications, and customer data seriously. We welcome contributions from security researchers, clients, and independent third parties to help us maintain a secure environment.
This policy outlines our guidelines for responsibly discovering and reporting security vulnerabilities in our software and web applications.
If you believe you have discovered a security vulnerability in any application or web service operated by Wu Wo Partnership Limited, please report it to us as soon as possible.
Security Email: support+security@wu-wo.co.uk
Security Manifest (RFC 9116): https://wu-wo.co.uk/.well-known/security.txt
What to Include in Your Report: To help us triage and validate the issue efficiently, please include:
When you report an issue to us following this policy, we commit to the following response timeline:
We consider security research conducted in good faith to be authorized and beneficial. If you comply with the following guidelines during your research, we will not pursue legal action or refer matters to law enforcement:
This policy applies to all web applications, APIs, and cloud services owned and operated by Wu Wo Partnership Limited.
Third-party services or infrastructure hosted independently by external providers (e.g., AWS core infrastructure, external SaaS tools) are subject to those respective providers' disclosure policies.