Found something? Tell us
If you have found a security flaw in our systems or software, we want to know. We handle the report factually and get back to you.
How to report
Send the report to security@wfsecurity.cloud. Write in Swedish or English, and include enough for us to reproduce the problem.
What helps us
- Which system or product it concerns
- What you did, step by step
- What you expected and what happened instead
- What impact you assess the flaw to have
- The time and any IP address you worked from
Our part
We confirm that we have received the report, assess it and come back with our conclusion. If the flaw is real we fix it and tell you when it is done.
We will not take legal action against anyone who reports in good faith and stays within the boundaries below. If you would like to be credited once the flaw is fixed, we are happy to do so. If you prefer to stay anonymous, we respect that.
We do not run a formal bug bounty programme with payouts.
What is fine and what is not
Please do
- Test against your own accounts and devices
- Report as soon as you have found something
- Give us reasonable time to fix it before telling others
- Describe the problem as clearly as you can
Please do not
- Test against other customers' accounts or data
- Run denial-of-service tests against production
- Read, change or delete data that is not yours
- Social engineering against our staff or customers
If it is something happening right now and affecting customers, write "URGENT" in the subject line to security@wfsecurity.cloud and the matter is prioritised.
Send your report
We read everything that arrives at the security address.