Beta draft — last updated 2026-07-01

Vulnerability disclosure

How to report

If you believe you've found a security vulnerability in WombatOps, please tell us before disclosing it publicly: hello@wombatops.com.

What to include

  • A description of the issue and why you believe it's a vulnerability.
  • Steps to reproduce it.
  • Any proof-of-concept — please avoid accessing, modifying, or exfiltrating real customer data beyond what's strictly needed to demonstrate the issue.

What to expect

We'll acknowledge your report and investigate in good faith, and keep you updated as we work on a fix. We're a small team in beta, so response times may vary — we don't have a formal SLA for this yet.

No bug bounty program

We're not offering paid rewards for reports at this time.