1. Our Commitment

Data Watchdog values good faith security research that helps protect readers, contributors, sources, editorial systems, and other technology controlled by the publication.

This policy explains how researchers can report suspected security vulnerabilities affecting Data Watchdog systems and the conditions under which authorized research may be treated as good faith security testing.

This policy does not grant permission to access third party systems, disrupt services, obtain unrelated information, or violate applicable law.

When the appropriate scope is uncertain, researchers should stop testing and contact:

security@datawatchdog.org

before proceeding.

2. Scope

In scope are datawatchdog.org and any subdomains, applications, systems, or services that Data Watchdog expressly identifies as being controlled by the publication.

Third party hosting, analytics, payment, advertising, content delivery, social media, email, embedded services, and other externally operated systems are outside the scope of this policy unless Data Watchdog explicitly confirms otherwise.

If a report concerns a third party provider but may materially affect Data Watchdog users, researchers may send a minimal description of the issue.

Data Watchdog may coordinate with the relevant provider where appropriate, but this policy does not authorize security research or testing against systems controlled by that provider.

3. Good Faith Research Conditions

Researchers should make a genuine effort to avoid privacy violations, destruction of data, service degradation, financial harm, and access beyond what is reasonably necessary to demonstrate a suspected vulnerability.

Use the smallest practical proof of concept.

If sensitive information is encountered unexpectedly, stop testing and do not retain, copy, publish, or share information that is unnecessary to demonstrate the vulnerability.

Researchers must not:

  • Exploit a vulnerability beyond the level reasonably necessary for verification
  • Establish persistence or maintain unauthorized access
  • Pivot into unrelated systems
  • Alter or delete website content or system data
  • Access private editorial material
  • Read confidential source communications
  • Download databases or bulk datasets
  • Perform denial of service or destructive testing
  • Send spam or excessive automated requests
  • Conduct phishing or social engineering
  • Test physical security without explicit authorization
  • Upload malware or malicious payloads
  • Demand payment as a condition of withholding disclosure
4. Safe Harbor Statement

Where security research is conducted in good faith, remains within the scope of this policy, avoids unnecessary harm, and is reported promptly through the disclosure process, Data Watchdog will not initiate legal action solely because the researcher performed activity authorized by this policy.

If a third party initiates action and the research complied with this policy, Data Watchdog may, where appropriate and lawful, clarify that the activity was conducted as part of its vulnerability disclosure process.

This safe harbor does not bind third parties, regulators, or law enforcement authorities.

It does not protect malicious, extortionate, reckless, deliberately harmful, out of scope, or otherwise unlawful conduct.

5. How to Report

Security reports should be sent to:

security@datawatchdog.org

Please use the subject line:

Security vulnerability report

Where possible, include:

  • The affected URL, application, system, or asset
  • The type of vulnerability
  • Steps required to reproduce the issue
  • Observed and potential impact
  • Date and time of testing
  • Relevant browser, operating system, tool, or environment information
  • A proof of concept that minimizes exposure
  • Any suggested remediation or mitigation

Do not attach large databases, private messages, identity documents, credentials, or unnecessary personal information.

If sensitive evidence is necessary, request an encrypted communication channel before sending it.

Data Watchdog should maintain a valid /.well-known/security.txt file identifying the current security contact, applicable policy URL, preferred language, and relevant expiry information.

6. Response Targets

Data Watchdog aims to:

  • Acknowledge credible security reports within three business days
  • Provide an initial assessment within ten business days
  • Communicate material status changes while remediation is underway

These are response targets rather than guarantees.

Complex vulnerabilities, third party dependencies, holidays, active incidents, infrastructure limitations, or other circumstances may require additional time.

Vulnerabilities may be prioritized according to exploitability, affected data, potential user impact, required privileges, affected scope, persistence, and availability of mitigations.

7. Coordinated Disclosure

Researchers should allow a reasonable period for assessment and remediation before publicly disclosing a vulnerability.

Data Watchdog will seek to discuss an appropriate disclosure timeline in good faith.

Immediate public disclosure may be justified in exceptional circumstances where users face active harm and the publisher is unresponsive.

However, unnecessary publication of exploit details, credentials, private information, or operational security details can increase risk and should be avoided.

Data Watchdog may credit a researcher with their consent after remediation.

The publication does not promise payment, a bounty, employment, public recognition, or other compensation unless such terms have been agreed in writing before the claim is made.

8. Out of Scope Findings

The following are generally outside the scope of this disclosure process:

  • Missing security headers without demonstrated security impact
  • Clickjacking on pages without sensitive actions
  • Self XSS
  • Rate limit observations without meaningful exploitation or impact
  • Automated scanner results without validation
  • Username enumeration without additional security impact
  • Email authentication observations without evidence of exploitability
  • Vulnerabilities existing solely within unsupported third party components not controlled by Data Watchdog

An issue being classified as out of scope does not necessarily mean that it has no security value.

Data Watchdog may still review an out of scope finding where the reported evidence indicates a credible risk to users, systems, or confidential information.

9. Incident and Privacy Handling

Security reports may be shared only with individuals, service providers, or professional advisers who reasonably need the information for security assessment, remediation, legal compliance, insurance, or incident response.

Security records may be retained for security, accountability, audit, and legal purposes.

Personal information contained in a security report should be minimized and handled in accordance with the Data Watchdog Privacy Policy.

Researchers should avoid including unnecessary personal or confidential information in vulnerability reports.

10. Contact

Security reports:
security@datawatchdog.org

Privacy concerns unrelated to a vulnerability:
privacy@datawatchdog.org

Editorial safety or source security concerns:
editorial@datawatchdog.org

For security vulnerabilities, researchers should use the dedicated security address wherever possible so that reports reach the appropriate responsible function promptly.