Security Disclosure Policy
How to report a security weakness in Warsha, what is in scope, and what Warsha promises in return.
العربية1. Reporting
Report through the security route in the Legal Contact document. Include what you found, how to reproduce it, and what it lets someone do.
Report before publishing. Warsha will acknowledge, keep you informed, and agree a disclosure timeline with you.
2. What Warsha promises
Warsha will not pursue legal action against someone who reports in good faith, stays within the rules below, and gives Warsha a reasonable chance to fix the problem before publishing.
Warsha will acknowledge the report, tell you what it found, and tell you when it is fixed.
Warsha will credit you if you want to be credited.
Warsha operates no paid bug bounty. It says so rather than leaving it ambiguous.
3. Rules
Testing must stay within these limits:
- Use only accounts you own. Do not access, modify or download another person's data.
- If you reach real personal data, stop immediately, do not save it, and say so in your report.
- No denial of service, no load testing, no spam, and nothing that degrades the service for other people.
- No social engineering of Warsha staff, workers or customers, and no physical intrusion.
- Do not use an automated scanner against production.
4. Scope
In scope: the Warsha applications, the API, authentication, access control, and anything that exposes personal data.
Out of scope: findings against a supplier's own infrastructure — report those to the supplier. Also out of scope: missing hardening headers with no demonstrated impact, and reports produced solely by a scanner with no analysis.
5. What Warsha does not claim
Warsha has not commissioned a penetration test and holds no security certification. This policy is a channel for reports, not evidence of an assessment.