Vulnerability Disclosure Program
We take security seriously. If you discover a vulnerability in StoryWonderBook, we encourage responsible disclosure. Valid reports are acknowledged publicly in our Hall of Fame.
In Scope
- Cross-site scripting (XSS)
- SQL injection
- Authentication bypass
- Privilege escalation
- Sensitive data exposure
Out of Scope
- Social engineering attacks
- DoS / DDoS attacks
- Spam or phishing
- Physical security attacks
Response Time
- Acknowledge within 48 hours
- Status update within 7 days
- Fix timeline communicated
Guidelines
- No data destruction or exfiltration
- No disruption to production systems
- No public disclosure before fix
- One account for testing only
Submit a Report
Hall of Fame
Researchers who responsibly disclosed valid vulnerabilities.
Be the first to report a valid vulnerability.