Skip to content

Vulnerability Disclosure Policy

September 16, 2026

Security and privacy are Whistic's primary objectives. We employ a variety of tools and processes to continually analyze and improve our security practices. However, no team can stay ahead of every potential vulnerability, and we welcome security research on our Services.

Testing is authorized only against our staging environment. The following hosts are in scope:

  • console.whistic.co
  • auth.whistic.co
  • public.whistic.co
  • mcp.whistic.co
  • Other hosts on the whistic.co domain

Production is not in scope. This includes console.whistic.com, auth.whistic.com, public.whistic.com, mcp.whistic.com, www.whistic.com, every other host on the whistic.com domain, and any third party service used by Whistic. Findings against these will not be accepted, and testing them is not covered by the safe harbor terms in this policy. If you are unsure whether something is in scope, ask at security@whistic.com before testing.

We provide safe harbor for the Computer Fraud and Abuse Act ("CFAA") and the Digital Millennium Copyright Act ("DMCA"), as well as any similar or successor legislative actions, for all research that is conducted in good faith and in compliance with this policy. We also permit and encourage coordinated disclosure of vulnerability findings, as long as such disclosures do not violate the confidentiality of any in scope or Whistic customer data and are agreed in writing with Whistic in advance.

Legal Terms

By participating in this policy, you agree to and are bound by the terms and conditions detailed in this page. These terms are governed by Delaware law, and constitute the entirety of the agreement between you and Whistic. Any changes to the terms in this policy must be made in writing and agreed upon by both parties.

Whistic will not publicly disclose the identity of any researcher that reports a vulnerability through this policy without their consent unless required to do so by law.

If litigation is initiated against you by a third party based on your disclosure(s) and your actions are fully in compliance with the terms and conditions of this policy, Whistic may, at its own and sole discretion, take reasonable steps to notify concerned parties that your actions were conducted in full compliance with our policy.

Unless Whistic is required by federal, state, or local law enforcement, Whistic does not intend to pursue legal action against research, researchers, or disclosures that are conducted in good faith, adhere to the strictest standards of confidentiality in terms of data ownership, and meet Whistic Terms of Service.

Conducting research and testing

Automated vulnerability scanning tools are strictly prohibited, and may result in being banned from further research participation and/or legal action where applicable.

You may only conduct research and tests against in scope hosts, using a user account you created for that purpose. You may not attempt to gain access to any other user's account. You may not compromise or attempt to compromise any other user's account or any confidential information that is owned by Whistic.

All research and tests must not disrupt, intercept, or compromise any data that you do not own, or violate any international, federal, state, or local laws or regulations. Keep request volume to what is needed to demonstrate a finding. Rate limit and denial of service testing is not permitted.

In the event of an inadvertent violation or disruption of service (e.g. you access another user's data, change any service configurations, etc.), immediately report the incident to security@whistic.com. Any and all data that was accessed during the course of research or testing must not be recorded, stored, used, disclosed, or further accessed in any way.

Disclosure Reporting Procedures

If you have discovered a vulnerability, please collect and send as many of the following points as possible to security@whistic.com:

  • Affected host and endpoint(s)
  • Detailed steps to replicate the vulnerability, including exact requests and responses
  • Screenshots of the UI, console, or tool dashboards throughout the collection and analysis process
  • Your assessment of impact

Whistic will acknowledge receipt of your report within ten business days. We will validate the finding, assign a severity, and communicate our assessment to you. Please keep all communication about a report to the original email thread.

Coordinated Disclosure

All submissions require explicit written permission from an authorized Whistic representative before any public disclosure of the results of a submission. Whistic supports coordinated disclosure, meaning the content, timing, and any researcher credit are agreed in writing by both parties before publication.

Any public disclosure made without explicit written permission from Whistic falls outside this policy, forfeits its protections, and will disqualify the reporter from all future participation.

Encouraged Submission Types

  • OWASP Top 10
  • Business Logic vulnerabilities
  • Information Disclosure
  • Data Exposure
  • Authorization/authentication issues, including OAuth and session handling
  • Product weaknesses that make phishing or account takeover easier

Excluded Submission Types

  • Findings against production or any out of scope host
  • Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, including rate limit testing
  • Spam reports
  • Phishing, vishing, or spear phishing campaigns targeting Whistic employees, customers, or partners
  • Social engineering reports
  • Open ports, version banners, or missing headers with no accompanying demonstration or proof of concept of vulnerability
  • Findings generated by automated tools without detailed explanation on what parts are vulnerable and how the vulnerability might be exploited
  • Issues in third party services not controlled by Whistic

Recognition

Due to resource constraints, we are not currently offering financial rewards for bug bounty submissions. Upon request, we can provide recognition letters as a demonstration of our gratitude for your contributions to our security efforts. With your consent, we will credit you when a fix is published.

Disclaimers

This policy does not permit monetary rewards for submissions. Submission of a report does not immediately qualify the submitter(s) for rewards or recognition in any form.

Whistic reserves the right to change, remove, or modify the terms and conditions of this policy at any time, with or without notice. Before sending each submission, please review the terms of this policy to ensure full compliance. Submitting reports outside of stated reporting procedures, testing out of scope hosts, or submitting excluded submission types will result in a temporary ban; continued or severe instances of abuse or non compliance will result in a permanent ban.

Whistic does not guarantee any response or remuneration for reported vulnerabilities. However, Whistic will make our best effort to acknowledge receipt of the reported vulnerability and other pertinent and disclosable information to the reporter as Whistic Security Team availability permits. Factors that influence the response timeline include the severity, likelihood, and impact of the vulnerability, as well as the current obligations and priorities of the Whistic Security team.

The future of risk and trust starts here

See how Whistic connects risk intelligence, automated workflows, compliance proof, and customer trust.

Certifications and Security Partnerships

Iso 27001 Iso 42001 Nist Gdpr compliant Shared assessments Aicpa soc2 Start level one Tx ramp