Vulnerability Disclosure Policy
How to responsibly report security issues to SignWow.
Vulnerability Disclosure Policy
Effective Date: 1 October 2026
Company Name: SignWow Ltd
Company Number: SC721510
Registered Office: 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom
1. Introduction
SignWow Ltd (“SignWow”, “we”, “us” or “our”) takes the security of our services and our users' data seriously. We welcome reports from independent security researchers who discover potential vulnerabilities in our systems, and we are committed to working with you to resolve them.
2. How to Report a Vulnerability
Please send your report by email to geeks@signwow.co.uk. To help us investigate, please include:
- A description of the vulnerability and its potential impact
- The affected URL, application, version or component
- Clear steps to reproduce the issue, including any proof of concept
- Your contact details, so we can follow up with you
Reports may be submitted in English.
3. Scope
This policy applies to websites, applications and services operated by SignWow, including www.signwow.co.uk and the SignWow mobile applications.
Services operated by third parties are not covered by this policy and should be reported to the relevant provider.
4. Guidelines for Researchers
When investigating and reporting issues, please:
- Only test against accounts and data you own or have explicit permission to use
- Avoid accessing, modifying or deleting other users' data, and stop testing immediately if you encounter personal information
- Do not perform denial of service, spam, social engineering or physical attacks
- Do not use automated scanning that degrades the performance of our services
- Give us reasonable time to resolve the issue before disclosing it publicly
5. Our Commitment
If you report a vulnerability in line with this policy, we will:
- Acknowledge receipt of your report
- Investigate the issue and keep you informed of our progress
- Work to resolve confirmed vulnerabilities as quickly as reasonably possible
- Not pursue or support legal action against you for good-faith research that complies with this policy
6. No Bug Bounty Program
SignWow does not currently operate a paid bug bounty program. We are not able to offer financial rewards for vulnerability reports, but we genuinely appreciate the time and effort of researchers who help keep our users safe.
7. Contact
Our security contact details are also published at /.well-known/security.txt.