Security
Last updated 24 August 2026
We take the security of WhoWhy and our customers' data seriously. If you believe you have found a security vulnerability in WhoWhy, we want to hear from you, and we will work with you to resolve it.
Reporting a vulnerability
Please email denis@whowhy.io with the details. Include a description of the issue, the steps to reproduce it, the affected URL or component, and its potential impact. A proof of concept helps us confirm and fix the problem faster.
Our commitment
We will acknowledge your report within three business days, investigate promptly, keep you informed of our progress, and remediate confirmed issues as quickly as we reasonably can. We are grateful for reports made in good faith and are happy to credit you once an issue is resolved, if you would like.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, will not pursue legal action against you, and will work with you to understand and resolve the issue. Please act in good faith: avoid privacy violations, data destruction, and any disruption to the service; access only the minimum data needed to demonstrate an issue; and give us reasonable time to fix a problem before disclosing it publicly.
Scope
This policy covers whowhy.io, app.whowhy.io, and the WhoWhy Slack application. Please avoid denial-of-service testing, spam, social engineering of our staff or customers, and physical attacks. Findings in third-party services we rely on should be reported to those providers directly.
Contact
WhoWhy OU, Estonia. Security contact: denis@whowhy.io.