Coordinated Vulnerability Disclosure Policy WizzDev P.S.A. | Version 0.3 (draft) | Effective: 30.07.2026 | Contact: security@wizzdev.pl WizzDev develops embedded and cloud software for connected devices. We take the security of what we build seriously, and we value the work of security researchers who help us find and fix vulnerabilities. This policy explains what is in scope, how to report a vulnerability to us, what you can expect from us, and the legal safe harbor we extend to good-faith research. 1. Scope In scope: Software and firmware developed by WizzDev and identifiable as such Services and infrastructure operated by WizzDev, including this website (wizzdev.com, wizzdev.pl) and cloud systems we host on our own domains Vulnerabilities in third-party or open-source components as integrated into the above Special case - products of our clients: WizzDev develops software for device manufacturers. If you have found a vulnerability in a commercial product that contains our code, the product's manufacturer is the primary contact - please check the product documentation or the manufacturer's website for their vulnerability reporting channel. You may also report to us: we will acknowledge your report, inform the manufacturer without delay, and support the fix. In that case, decisions about public disclosure, advisories, and regulatory reporting rest with the manufacturer, and we will connect you with them for coordination. Out of scope: Systems and infrastructure operated by our clients or other third parties (report to their respective owners) Denial-of-service testing, physical attacks against offices or data centers, and social engineering of WizzDev staff or clients Findings without security impact (e.g., missing best-practice headers with no exploitable consequence, software version disclosure alone) Reports generated by automated scanners without validation or a plausible attack scenario 2. How to report Email security@wizzdev.pl. If your report contains sensitive details, ask us for an encrypted channel in a first message and we will provide one. Please include, where possible: The affected product, service, or domain, and version or firmware revision if known A description of the vulnerability and its security impact Steps to reproduce - a proof of concept, sample requests, or a minimal script help us triage faster Your assessment of severity, if you have one How you would like to be credited (or that you prefer to remain anonymous), and contact details for follow-up questions You may report anonymously; note that we cannot then update you on progress or credit you. Please do not include more user or client data in the report than necessary to demonstrate the issue. 3. Our commitments Acknowledgment within 48 hours of receiving your report Initial triage within 5 working days: we will tell you whether we have confirmed the issue, how we assess its severity, and what happens next We will keep you informed of progress at reasonable intervals until resolution, and tell you when the vulnerability is fixed We will not initiate legal action against you for research conducted in accordance with this policy (see Section 5) We will handle your report and personal data confidentially and will not share your identity without your consent, except where required by law With your consent, we will credit you by name or handle in any advisory we or the affected manufacturer publish 4. Coordinated disclosure We ask that you: Give us a reasonable period to remediate before any public disclosure - 90 days from your report is our default, and we will tell you early if a specific case needs more (for example, where a fix must be rolled out across a fleet of devices) or can be done sooner Coordinate the content and timing of any publication with us and, where a client's product is affected, with the manufacturer Do not access, modify, or delete data beyond what is strictly necessary to demonstrate the vulnerability; if you encounter personal data or confidential information, stop, do not store or share it, and tell us Do not degrade the availability of our or our clients' systems Vulnerabilities in products placed on the EU market may be subject to regulatory reporting duties under the Cyber Resilience Act (Regulation (EU) 2024/2847). Those duties rest with the product's manufacturer; we support their fulfilment. This does not change anything about how you report to us. 5. Safe harbor We consider security research conducted in good faith and in accordance with this policy to be authorized. Specifically, if you make a genuine effort to comply with this policy: We will not initiate or support legal action against you (civil or criminal) for your research, and we will not report your activity to law enforcement, unless we are legally obliged to We waive any claim based on the circumvention of technical protection measures, to the extent such waiver is permitted by law, where the circumvention was necessary for the research If a third party initiates legal action against you in connection with research conducted under this policy, we will make it known that your activity was conducted in accordance with this policy Good faith means, at minimum: no exploitation beyond what is needed to demonstrate the issue, no data exfiltration, no extortion or coupling of the report to demands for payment, no degradation of service, and prompt reporting to us. This safe harbor does not apply to activity that violates the law independently of this policy, and it cannot bind third parties; where a client's product is involved, we will advocate that the client honor equivalent terms. We do not currently operate a paid bug bounty program. Reports are received with gratitude and, where you wish, public credit - not with monetary reward. 6. Questions Questions about this policy: security@wizzdev.pl. This policy may be updated; the current version is always at (https://wizzdev.com/cvd-policy/) and referenced from our /.well-known/security.txt files.