Security

Responsible Disclosure

Security is central to what we do at WebInspect, and we appreciate responsible reports from security researchers and members of the community who identify potential security issues affecting WebInspect.pro. If you believe you have discovered a security vulnerability in WebInspect, please report it to us so we can investigate and address the issue.

Reporting a Vulnerability

When submitting a security report, please provide enough information for us to understand and reproduce the issue where possible. Useful information may include:

Please avoid including unnecessary personal information or sensitive data in your report.

Responsible Testing

We welcome good-faith security research involving WebInspect systems, provided that testing is conducted responsibly. When investigating a potential vulnerability, please:

Third-Party Websites

This Responsible Disclosure Policy applies only to vulnerabilities affecting WebInspect's own systems and services. The fact that a website can be inspected using WebInspect does not mean that WebInspect owns, operates, or authorizes security research against that website.

Security vulnerabilities discovered on third-party websites should be reported directly to the organization responsible for the affected system and in accordance with that organization's disclosure policy. WebInspect must not be used as authorization to perform intrusive testing or attempt to exploit vulnerabilities on third-party systems.

What You Can Expect From Us

For reports submitted in good faith, we will make reasonable efforts to:

We ask researchers to allow reasonable time for investigation and remediation before making vulnerability details public.

Rewards

WebInspect does not currently operate a bug bounty or paid vulnerability reward program. Submitting a vulnerability report does not create an entitlement to payment, compensation, or other reward.

We nevertheless appreciate responsible security research that helps us improve the security of WebInspect and its users.

Contact

Security vulnerabilities affecting WebInspect should be reported to:

security@webinspect.pro

Please clearly identify your message as a security vulnerability report so that it can be reviewed appropriately.