Responsible Disclosure Policy
Wiki welcomes good-faith security research that helps protect our customers and platform.
Effective July 10, 2026
This Responsible Disclosure Policy (“Policy”) describes how security researchers may report suspected vulnerabilities in Wiki-owned systems. Wiki, a company organized under the laws of the State of Montana, is committed to working with the security community to address legitimate security concerns.
Scope
- Wiki application, marketing website, and Wiki-operated infrastructure.
- Authentication, billing integrations, and core API routes operated by Wiki.
- Not in scope: third-party services, customer content and configurations, customer-hosted documentation policies, social engineering of Wiki employees or customers, or physical security testing without prior written authorization.
Authorization and Safe Harbor
If you conduct security research in accordance with this Policy, Wiki will not initiate legal action against you for unauthorized access or circumvention of technological measures, provided that you:
- Act in good faith and comply with all applicable laws.
- Do not access, modify, delete, or exfiltrate data belonging to other customers or Wiki personnel.
- Do not degrade, disrupt, or impair the availability or integrity of the Service.
- Do not engage in social engineering, phishing, or physical intrusion against Wiki personnel, facilities, or customers.
- Do not publicly disclose vulnerabilities before Wiki has had a reasonable opportunity to investigate and remediate.
This safe harbor applies only to research conducted in compliance with this Policy and does not extend to conduct outside the defined scope. Wiki reserves all rights against individuals who violate this Policy or applicable law.
Reporting Requirements
Email security@wiki.co with a detailed report. Include, to the extent possible:
- Description of the vulnerability and potential impact.
- Steps to reproduce, including affected URLs, parameters, and proof of concept.
- Your contact information for follow-up.
- Confirmation that you agree to comply with this Policy.
Our Process
Wiki will acknowledge receipt of valid reports within a reasonable timeframe and investigate in priority order based on severity and exploitability. Wiki does not guarantee a specific remediation timeline. Wiki may, at its sole discretion, offer recognition or compensation for exceptional reports, but no bug bounty program is offered unless separately announced in writing. Participation in any such program is subject to its published terms.
Governing Law
This Policy is governed by the laws of the State of Montana. Disputes arising from security research conducted under this Policy are subject to the dispute resolution provisions in Wiki’s Terms of Service.
Report a vulnerability