Effective date: 2026-05-18.
wrxstack believes security is a collaboration. We invite security researchers to help us keep our users safe through coordinated disclosure under the rules below. This page is also referenced from /.well-known/security.txt.
1. Scope
In scope
wrxstack.com(the marketing site),atlas.wrxstack.com(Atlas), andportfolio.wrxstack.com(Portfolio), and their supporting API and authentication endpoints.
Out of scope
- Any subdomain or service operated by a third party on our behalf;
- Social-engineering attacks against any person (including phishing, vishing, smishing);
- Denial-of-service, volumetric, or stress testing;
- Spam, content-injection, or self-XSS issues that require unrealistic user interaction;
- Issues that require a rooted, jailbroken, or otherwise compromised end-user device;
- Best-practice or hardening suggestions that are not a vulnerability (for example, a missing HTTP header where no exploit path exists).
2. Rules of engagement
- Test only against accounts you own or are authorized to test;
- Do not access, modify, or destroy data that does not belong to you. If you encounter data that does not belong to you, stop testing and report immediately;
- Do not run automated scans that generate meaningful traffic without prior coordination;
- Do not publicly disclose a finding before we have had a reasonable opportunity to remediate (typically 90 days). We will work with you on coordinated disclosure timing for high-impact findings;
- Comply with all applicable laws.
3. Safe harbor
If you make a good-faith effort to comply with this Policy during your security research, we:
- will consider your research to be authorized in accordance with the Computer Fraud and Abuse Act ("CFAA"), the DMCA anti-circumvention provisions for the purpose of accessing the work, and similar laws to the extent they would otherwise restrict your activity;
- will not pursue or support any legal action against you;
- will work with you to understand and resolve the issue quickly, and will publicly recognize your contribution if you wish.
This safe harbor does not authorize activity that is otherwise illegal, that violates the rights of third parties, or that violates the AUP, and it does not bind any third party. If in doubt, contact us before testing.
4. No monetary reward
We do not operate a paid bug bounty and we do not pay monetary rewards for reports. We are grateful for good-faith research and, with your permission, will credit you when we publicly acknowledge a fix.
5. How to report
Email contact@wrxstack.com with the subject line "Security" and include:
- A clear description of the issue and the impact;
- Steps to reproduce, with a proof of concept where possible;
- The affected URL or endpoint;
- The account you tested with;
- Your preferred contact channel and pseudonym (if any) for credit.
6. Contact
For any question about this Policy, contact contact@wrxstack.com with the subject line "Security".