Security Policy
If you have discovered a security vulnerability, please report it responsibly. We aim to acknowledge reports within 3 business days and, where practical, provide an initial assessment or next steps within 10 business days.
Security Approach
We use reasonable technical and organizational safeguards appropriate for a small hosted application. No internet service can be guaranteed completely secure, but we work to reduce risk through HTTPS, hashed passwords, restricted administrative access, backups, software updates, and monitoring.
Our Commitment
Amar Micro Inc. takes the security of wed.money and its users seriously. We aim to:
- Address confirmed vulnerabilities promptly with security updates;
- Notify registered users of critical security issues when appropriate or legally required;
- Practice responsible coordinated disclosure;
- Credit researchers who report responsibly (unless anonymity is requested).
Scope
This policy covers vulnerabilities in:
- The wed.money application (all PHP, JS, SQL components);
- The wed.money website and API at https://wed.money.
Out of scope:
- Third-party libraries (report those to their maintainers);
- Social engineering or phishing attacks;
- Denial-of-service attacks.
Reporting a Vulnerability
Please do not report security issues through public forums, social media, or support channels.
Report privately to:
Security Contact: security@wed.money
What to Include
- Type of vulnerability (SQL injection, XSS, authentication bypass, CSRF, etc.);
- Affected component or URL;
- Step-by-step reproduction instructions;
- Proof-of-concept or screenshots if available;
- Potential impact;
- Your name/handle for credit, or a request for anonymity.
Disclosure Process
| Target timeframe | Action |
|---|---|
| Aim: around 3 business days | Acknowledge receipt |
| Aim: around 10 business days | Provide an initial assessment, decline rationale, or next steps |
| Aim: around 30 days | Provide remediation direction or status for confirmed issues |
| When practical after patch release | Notify you so you can verify the fix |
| When appropriate (often around 90 days after patch) | Coordinated public disclosure (if researcher desires) |
Safe Harbor
We will not pursue legal action against researchers who:
- Report in good faith through this policy;
- Avoid privacy violations, data destruction, and service disruption;
- Do not exploit the vulnerability beyond minimal proof of concept;
- Test only against their own account, not other users' data.
Safe harbor does not apply to activities that violate law regardless of intent, such as accessing another user's account or data without authorization.
Out of Scope Issues
The following will generally not be accepted:
- Issues requiring physical access to a server;
- Reports from automated scanners without verified exploitability;
- Missing security headers with no demonstrable impact;
- Issues requiring the attacker to already have full account access;
- Vulnerabilities in third-party libraries (report to those projects).
Hardening Your Account
We recommend these practices to keep your account secure:
- Use a strong, unique password not shared with other services;
- Do not share your credentials with celebration members — invite them instead;
- Log out when using shared or public computers;
- Contact us immediately if you notice unfamiliar account activity.
Security Updates
Security fixes are deployed to the hosted service. For critical incidents, we aim to communicate with affected users promptly once we have enough verified information to provide useful guidance.