Security
Responsible security reporting
Report a vulnerability
Email admin@wks-hq.com with a concise description, affected version or URL, reproduction steps, and impact. Do not include production secrets, payment-card data, or unrelated personal information.
Research boundaries
Do not access, modify, retain, or disclose other people's data; disrupt production; use social engineering; test physical security; perform denial-of-service activity; or demand payment. Use your own accounts and data. Stop and report immediately if you encounter information that is not yours.
Coordinated handling
Publisher will acknowledge a credible report, investigate, and coordinate a reasonable disclosure timeline based on severity and remediation needs. Do not publicly disclose an unresolved issue before coordination. This policy does not authorize activity that violates law or third-party terms.
Incident response
Publisher will investigate suspected compromise of publisher-operated services, take reasonable containment and remediation steps, preserve appropriate records, and provide legally required notices. Kentucky residents will be notified as required by applicable Kentucky breach-notification law.
Shared responsibility
Customers are responsible for securing their servers, devices, operating systems, network access, backups, credentials, email, and payment-provider accounts. Customers must promptly install appropriate security updates, limit administrator access, and securely dispose of exported data. Publisher security controls do not replace those duties.