Skip to main content
Wavelink — One Tap. Endless Connections.
About The card Pricing Custom Voices Markets Connect FAQ Help & Support
Start at $29
Security · Researchers · Welcome

Help us stay sharp.

Found something? Tell us. We respond within 72 hours, give you safe harbor, and credit you in our Hall of Fame if you want.

ISO/IEC 29147 · 30111 EU Cyber Resilience Act disclose.io core terms RFC 9116 · security.txt
Last updated 29 September 2026 Version v1.2.0 We reply within 72 hours. Safe harbor
On this page
  • 01 Our promise
  • 02 In & out of scope
  • 03 How to report
  • 04 Safe harbor
  • 05 Severity & response times
  • 06 Hall of fame
  • 07 Out of bounds
01

Our promise

If you follow this policy when reporting a vulnerability to us, we will:

  • Acknowledge your report within 72 hours, business or not.
  • Triage and give you an initial assessment within 5 business days.
  • Keep you informed of our progress at least every 14 days until the issue is fixed.
  • Credit you in our Hall of Fame if you ask (and as long as your report complies).
  • Treat your report as confidential. We will not share your name or report outside the team that needs to know.
  • Not pursue legal action against you for the act of reporting, when you have followed this policy.

This policy is aligned with ISO/IEC 29147 and ISO/IEC 30111, the disclose.io core terms, and the EU Cyber Resilience Act disclosure expectations.

02

In & out of scope

In scope
  • getwaved.ai and all subdomains in production.
  • The Wavelink profile pages served from our domain.
  • Our Cloudflare Pages Functions (the API powering forms, geo lookup, lead capture).
  • The Cloudflare Worker that handles asset routing.
  • Our mobile-web experience (no native app is in production).
Out of scope
  • Third-party platforms we link to (WhatsApp, Facebook, Instagram, YouTube, TikTok, X).
  • Cloudflare's own platform — report those to Cloudflare.
  • Microsoft Clarity analytics — report to Microsoft.
  • Denial-of-service, rate-limiting bypasses against non-PII endpoints.
  • Self-XSS, missing security headers on third-party assets.
  • Issues that require a rooted device, jailbroken phone, or compromised network.
03

How to report

Send a clear, reproducible report. The format below lets us act fastest.

Report template

  1. Title — Title — one line, what is the issue.
  2. Asset — Asset — URL or component affected.
  3. Severity — Severity — your estimate (Critical / High / Medium / Low).
  4. Description — Description — what is the issue and what is the impact.
  5. Steps to reproduce — Steps to reproduce — exact steps we can follow.
  6. Proof of concept — Proof of concept — screenshot, video, or command output.
  7. Suggested fix — Suggested fix — optional but very welcome.
  8. Your handle — Your handle — for Hall of Fame credit, if you want it.

Where to send

  • Email: [email protected]
  • PGP fingerprint: 2B7E 5F19 8C4A 1D83 (rotates quarterly)
  • Signal: request from [email protected]

Reports are read by a member of our engineering team. We never outsource triage.

04

Safe harbor

When you conduct research and submit a report under this policy, we consider the research to be:

  • Authorised under our Terms of Service — we will not bring a claim against you for the act of reporting.
  • Exempt from the UAE Federal Decree-Law No. 34 of 2021 restrictions on unauthorised access, provided your testing was strictly necessary to demonstrate the vulnerability and you caused no harm beyond what the demonstration required.
  • Aligned with "good faith" research exceptions in EU, UK, US (CFAA), and Singapore cybersecurity laws.

If your research inadvertently accesses personal data

stop, do not download, and tell us. We will work with you to delete or quarantine any data created by your activity.

This safe harbor extends only to research that complies with this policy. It does not cover unrelated criminal activity, extortion, or publication of a vulnerability before we have had a reasonable time to fix it.

05

Severity & response times

We classify by impact, using the CVSS v3.1 base score as a starting reference.

SeverityExampleOur target
CriticalAccount takeover, PII mass exposureAcknowledge in 24h · Fix in 7 days
HighStored XSS, authentication bypassAcknowledge in 72h · Fix in 30 days
MediumReflected XSS, missing rate limitAcknowledge in 5 days · Fix in 60 days
LowInformation disclosure, hardeningAcknowledge in 7 days · Fix in next release

"Fix" means deployed to production. We notify you when the fix ships.

06

Hall of fame

Researchers who report a valid, previously-unknown vulnerability may be added to our Hall of Fame if they wish. We never publish reports without consent.

The Hall of Fame is opened to entries from the first quarter of 2027, once we have processed enough reports to make it meaningful. Researchers whose reports predate that are added retroactively on request.

07

Out of bounds

The following activities are not authorised under this policy and may remove safe harbor:

  • Public disclosure of a vulnerability before we have confirmed a fix.
  • Accessing, downloading, or modifying data beyond what is strictly necessary to demonstrate the issue.
  • Using a vulnerability to demand payment, ransom, or any form of consideration.
  • Testing on production systems in a way that degrades service for other customers.
  • Social engineering or phishing of our staff.
  • Physical attacks against our offices, hardware, or staff.

This policy is referenced from /.well-known/security.txt as our disclosure policy under RFC 9116.

Wavelink — One Tap. Endless Connections.

Wavelink is the trust layer for every professional meeting. Tap-to-share smart business cards and Google Review stands for professionals across South Asia and the GCC. No app required.

WhatsApp Facebook YouTube TikTok Instagram X

Product

  • The card
  • Pricing
  • Bundles
  • Custom Design · Your brand
  • How it works
  • The platform
  • Voices
  • AbaYa-Track (YouTube)

Legal · Trust

  • Help & Support
  • Privacy Policy
  • Terms of Service
  • DPA Agreement
  • Refund Policy
  • Packaging & Sustainability
  • Sourcing & Provenance
  • AI Alchemist · Disclosure
  • Intelligence Drops · Terms
  • Anti-Fraud Disclaimer
  • Responsible Disclosure
  • FAQ

Regional entities

AEWavelink UAE
QAWavelink Qatar
BHWavelink Bahrain
BDWavelink Bangladesh (HQ)
CNWavelink Hangzhou

Markets

  • BD Bangladesh (Dhaka, Chittagong)
  • AE UAE (Dubai, Abu Dhabi, Ajman)
  • QA Qatar (Doha)
  • BH Bahrain (Manama)
  • CN Greater China (Hangzhou)
  • DE Germany (Berlin)
  • BR Brasil (São Paulo)
  • + 30+ countries via free delivery
Wavelink · Registered in Bangladesh · Shipping in 30+ countries · 2026 NFC POWERED CONNECTIONS
Found a vulnerability?
We reply within 72 hours.
Email security team