Found something? Tell us

If you have found a security flaw in our systems or software, we want to know. We handle the report factually and get back to you.

How to report

Send the report to security@wfsecurity.cloud. Write in Swedish or English, and include enough for us to reproduce the problem.

What helps us

  • Which system or product it concerns
  • What you did, step by step
  • What you expected and what happened instead
  • What impact you assess the flaw to have
  • The time and any IP address you worked from

Our part

We confirm that we have received the report, assess it and come back with our conclusion. If the flaw is real we fix it and tell you when it is done.

We will not take legal action against anyone who reports in good faith and stays within the boundaries below. If you would like to be credited once the flaw is fixed, we are happy to do so. If you prefer to stay anonymous, we respect that.

We do not run a formal bug bounty programme with payouts.

What is fine and what is not

Please do

  • Test against your own accounts and devices
  • Report as soon as you have found something
  • Give us reasonable time to fix it before telling others
  • Describe the problem as clearly as you can

Please do not

  • Test against other customers' accounts or data
  • Run denial-of-service tests against production
  • Read, change or delete data that is not yours
  • Social engineering against our staff or customers
Urgent ongoing incident?

If it is something happening right now and affecting customers, write "URGENT" in the subject line to security@wfsecurity.cloud and the matter is prioritised.

Send your report

We read everything that arrives at the security address.