Security

Responsible security reporting

Report a vulnerability

Email admin@wks-hq.com with a concise description, affected version or URL, reproduction steps, and impact. Do not include production secrets, payment-card data, or unrelated personal information.

Research boundaries

Do not access, modify, retain, or disclose other people's data; disrupt production; use social engineering; test physical security; perform denial-of-service activity; or demand payment. Use your own accounts and data. Stop and report immediately if you encounter information that is not yours.

Coordinated handling

Publisher will acknowledge a credible report, investigate, and coordinate a reasonable disclosure timeline based on severity and remediation needs. Do not publicly disclose an unresolved issue before coordination. This policy does not authorize activity that violates law or third-party terms.

Incident response

Publisher will investigate suspected compromise of publisher-operated services, take reasonable containment and remediation steps, preserve appropriate records, and provide legally required notices. Kentucky residents will be notified as required by applicable Kentucky breach-notification law.

Shared responsibility

Customers are responsible for securing their servers, devices, operating systems, network access, backups, credentials, email, and payment-provider accounts. Customers must promptly install appropriate security updates, limit administrator access, and securely dispose of exported data. Publisher security controls do not replace those duties.