Legal
Security reporting
Last updated: July 22, 2026
SignalWatch takes responsible security reporting seriously. Do not include classified, controlled or operationally sensitive information. Reports concerning this public website or SignalWatch software may be submitted to security@signalwatch.example.
Scope
This process covers this public website and SignalWatch software. It does not cover third-party services, and it is not a channel for general product questions — use the contact page for those.
What to include
A useful report contains enough detail for us to reproduce and assess the issue:
- The affected URL, page or software component.
- Step-by-step instructions to reproduce the issue.
- Your assessment of the impact — what an attacker could do and who would be affected.
- Any relevant environment details (browser, operating system, configuration), and a way to reach you for follow-up questions.
Please report through email only, keep testing non-destructive, and do not access, modify or retain data that is not yours.
Coordinated disclosure
We ask that you give us a reasonable amount of time to investigate and remediate a confirmed issue before disclosing it publicly. In return, we will acknowledge your report, keep you informed of progress where we can, and credit you for the finding if you wish once the issue is resolved.
No reward program
SignalWatch does not currently operate a bug-bounty or vulnerability-reward program, and no payment or reward is offered for reports. We say this plainly so there is no misunderstanding: reports are received with genuine appreciation, but on a goodwill basis.
Contact
Security reports: security@signalwatch.example. For all other matters, email contact@signalwatch.example.