Skip to content

Responsible disclosure

Last updated:

How to report a security vulnerability in Ward, and what you can expect from us.

1.What you can report

If you have found a security flaw in Ward (this website, its waitlist, the domain scan or any other service of ours), we would appreciate hearing about it before it becomes public. We are interested in, for example:

  • access to other people's or companies' data (mailing lists, scans, reports);
  • code injection into our pages (XSS) or our servers;
  • ways around the usage limits, or ways to use Ward to attack third parties;
  • flaws in encryption, security headers or session handling;
  • secrets or internal data exposed by mistake.

2.How to report it

Email onboarding@resend.dev, preferably in English or Spanish. So we can reproduce the problem, please include:

  • what you found and where (the address of the page or service);
  • the steps to reproduce it and, if you can, a minimal proof;
  • the impact you think it has;
  • how we can reach you.

You don't need to send us other people's data: showing that the access is possible is enough.

3.What to expect from us

We will try to acknowledge your report within five business days, tell you whether the problem is confirmed and keep you posted while we fix it. With your permission, we will credit you as the finder when we publish the fix. We don't run a bug bounty: we don't pay for reports.

We ask you to give us a reasonable time (generally up to 90 days) to fix it before you publish the details.

4.Rules for your research

If you research in good faith and follow these rules, we will not take legal action against you for it:

  • test only with your own accounts and data, never with anyone else's;
  • if you come across third-party data, stop, don't copy or use it and tell us;
  • don't run tests that degrade the service (denial of service, mass submissions, aggressive automated scans);
  • no social engineering, impersonation or physical attacks against our team or our providers;
  • don't act on third-party systems: our providers' services have their own policies.

This does not replace the law: conduct that breaks it is outside this policy.

5.What we don't need you to report

Automated reports with no demonstrated impact (for example, a missing header with no practical effect), flaws that require an already-compromised device, spam, or problems in third-party services we don't control. For questions about your personal data, see the Privacy Policy.