WristUnlock

Reporting a security problem

A vulnerability disclosure policy for WristUnlock. Linked from /.well-known/security.txt per RFC 9116.

This app can unlock a car. If you have found something that lets one person reach another person's vehicle, say so in the first line of your report and it will be treated as the highest priority — ahead of anything else in the queue.

Write to [email protected]. Plain email is fine; there is no form to fill in and no account to create.

What to expect

AcknowledgementWithin 72 hours. If you have not heard back in that time, assume the mail went astray and send it again — do not assume it was ignored.
First assessmentWithin 7 days: whether it reproduces, how severe we think it is, and what we intend to do.
FixVehicle-access issues are fixed ahead of all other work. Everything else is scheduled honestly rather than promised to a date we cannot keep.
CreditYou will be credited by whatever name you choose, or not at all if you prefer. Tell us which.
BountyThere is no bug bounty. This is a pre-revenue independent app and it would be dishonest to imply a payment that does not exist. Said plainly so nobody spends time expecting one.

What is in scope

What is not

Ground rules

Test against your own account and your own vehicle, never anyone else's. Do not access, modify or retain data that is not yours — if you reach someone else's data by accident, stop, and say so in the report. Give us a reasonable chance to fix the issue before publishing.

Report in good faith within these rules and we will not pursue you for it, and we will not ask you to sign anything to receive that assurance.

Where the answers already are

Some questions are answered without a report: what the app stores and for how long is in the Privacy Policy, what it can and cannot do is in Features, and the trademark and authorization position is in Legal.