Skip to main content

Vulnerability Disclosure Policy

How to responsibly report security issues to SignWow.

Vulnerability Disclosure Policy

Effective Date: 1 October 2026

Company Name: SignWow Ltd

Company Number: SC721510

Registered Office: 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom

1. Introduction

SignWow Ltd (“SignWow”, “we”, “us” or “our”) takes the security of our services and our users' data seriously. We welcome reports from independent security researchers who discover potential vulnerabilities in our systems, and we are committed to working with you to resolve them.

2. How to Report a Vulnerability

Please send your report by email to geeks@signwow.co.uk. To help us investigate, please include:

  • A description of the vulnerability and its potential impact
  • The affected URL, application, version or component
  • Clear steps to reproduce the issue, including any proof of concept
  • Your contact details, so we can follow up with you

Reports may be submitted in English.

3. Scope

This policy applies to websites, applications and services operated by SignWow, including www.signwow.co.uk and the SignWow mobile applications.

Services operated by third parties are not covered by this policy and should be reported to the relevant provider.

4. Guidelines for Researchers

When investigating and reporting issues, please:

  • Only test against accounts and data you own or have explicit permission to use
  • Avoid accessing, modifying or deleting other users' data, and stop testing immediately if you encounter personal information
  • Do not perform denial of service, spam, social engineering or physical attacks
  • Do not use automated scanning that degrades the performance of our services
  • Give us reasonable time to resolve the issue before disclosing it publicly

5. Our Commitment

If you report a vulnerability in line with this policy, we will:

  • Acknowledge receipt of your report
  • Investigate the issue and keep you informed of our progress
  • Work to resolve confirmed vulnerabilities as quickly as reasonably possible
  • Not pursue or support legal action against you for good-faith research that complies with this policy

6. No Bug Bounty Program

SignWow does not currently operate a paid bug bounty program. We are not able to offer financial rewards for vulnerability reports, but we genuinely appreciate the time and effort of researchers who help keep our users safe.

7. Contact

SignWow Ltd
5 South Charlotte Street
Edinburgh, EH2 4AN, United Kingdom

Our security contact details are also published at /.well-known/security.txt.