Watchmora
Security and Responsible Disclosure
Security reports help protect Watchmora and its users. Use the private Security form and avoid actions that could damage the service or expose other people’s information.
Effective date: 6 August 2026 · Last updated: 6 August 2026 · Version 2.2
What to report
Report suspected vulnerabilities involving authentication, authorisation, account takeover, data exposure, injection, cross-site scripting, request forgery, unsafe file access, private evidence, API access or another material security control.
Use ordinary Support for a login problem that does not involve a vulnerability.
What to include
Provide:
- the affected URL, feature or API route;
- a clear description of the issue and expected impact;
- safe reproduction steps;
- relevant browser or device information;
- limited screenshots or logs with secrets and personal information removed;
- whether you believe active exploitation is occurring.
Do not send passwords, authentication tokens, private keys or datasets containing personal information.
Testing boundaries
Do not:
- access, change or delete another person’s data;
- create persistence, malware or a backdoor;
- use denial-of-service, load or destructive testing;
- send spam or automated messages;
- socially engineer users or providers;
- test third-party services without their permission;
- download more data than minimally necessary to demonstrate the issue;
- publicly disclose an unresolved vulnerability before Watchmora has had a reasonable opportunity to investigate.
This Policy does not authorise unlawful access or override the terms of another service.
Good-faith reports
If you act in good faith, avoid harm, respect privacy and report promptly, Watchmora will consider the report responsibly and will not treat an accidental, minimal and non-destructive discovery as abuse merely because it was reported.
This is not a promise of immunity from law or from claims by third parties.
What happens next
Watchmora may acknowledge the report, request clarification, reproduce the issue, restrict affected functionality, preserve evidence, deploy a fix and ask you to verify the result.
Response time depends on severity, evidence and available resources. No bug bounty or payment programme is currently offered unless Watchmora agrees otherwise in writing before the work.
Privacy and credit
Tell us whether you want to remain private or be credited after resolution. Do not publicly identify affected users or disclose personal information.
Contact route
Submit reports through the Security form. The form creates a private case and supports controlled evidence handling.
To report a security vulnerability, use the security-report form or email [email protected]. Do not include unnecessary personal data, passwords, authentication codes or active exploit material in ordinary email.