FundWisr™ Vulnerability Disclosure Policy
Public Reporting Channel
FundWisr should publish:
- Security email:
support@fundwisr.ai - Web form:
https://www.fundwisr.ai/security/vulnerability-disclosure - Security.txt:
https://www.fundwisr.ai/.well-known/security.txt
The channel must accept reports without requiring a customer account, be monitored, support secure attachments, acknowledge receipt, preserve original submissions, and avoid collecting unnecessary personal information.
Good-Faith Safe Harbor
Subject to legal approval, FundWisr should state that it does not intend to pursue legal action against a researcher who:
- acts in good faith;
- follows this Policy;
- avoids harm;
- does not access more data than necessary;
- stops after confirming the issue;
- does not retain, copy, or share Customer Content;
- reports promptly;
- does not extort or demand payment;
- allows reasonable time for remediation;
- complies with applicable law.
Safe harbor does not authorize unlawful conduct or bind third parties.
In-Scope Systems
Potential in-scope assets include:
fundwisr.com;- the authenticated FundWisr application;
- designated API endpoints;
- designated subdomains;
- designated test environments;
- public forms hosted by FundWisr;
- security.txt-listed assets.
All exact domains and environments must be verified before publication.
Out-of-Scope Systems
Potentially out-of-scope systems include:
- third-party websites not controlled by FundWisr;
- customer-owned domains;
- customer-selected integrations;
- vendor infrastructure not operated by FundWisr;
- social-media accounts;
- employee personal accounts;
- physical offices;
- retired or unlisted environments.
A vendor-related report may still be accepted and routed, but the vendor's own policy may govern testing.
Permitted Testing
Permitted good-faith testing may include:
- authentication and authorization testing using researcher-controlled accounts;
- input-validation testing;
- harmless cross-site scripting payloads;
- API authorization testing;
- insecure direct object reference testing with test data;
- low-volume rate-limit testing;
- harmless file-upload validation;
- session-management testing;
- tenant-isolation testing using researcher-controlled workspaces;
- prompt-injection testing that does not access another customer's data;
- security-header review;
- public-source analysis.
Testing must stop when a vulnerability is confirmed.
Prohibited Testing
Unless FundWisr provides prior written authorization, prohibited activities include:
- denial-of-service testing;
- high-volume automated scanning;
- destructive testing;
- deleting or altering Customer Content;
- accessing another customer's data;
- social engineering or phishing;
- physical intrusion;
- malware or ransomware;
- extortion;
- credential stuffing;
- testing stolen credentials;
- persistent access;
- exfiltration;
- payment fraud;
- contacting customers about a report;
- public disclosure before coordination;
- modifying production data beyond a minimal proof.
Data Minimization by Researchers
Researchers must use test accounts and synthetic data, avoid real Customer Content, stop after minimal confirmation, redact sensitive information, delete local copies after confirmation, and notify FundWisr immediately if another person's data is encountered.
Required Report Information
A useful report should include:
- researcher name or alias;
- contact information;
- affected URL or component;
- vulnerability type;
- date and time observed;
- reproduction steps;
- impact;
- proof of concept;
- test-account identifiers;
- whether data was accessed;
- whether the issue remains active;
- suggested remediation;
- disclosure plans;
- relevant attachments or logs.
Reports should not include unnecessary Customer Content, passwords, payment-card data, or secrets.
Acknowledgment Targets
| Action | Target |
|---|---|
| Initial acknowledgment | Within 2 business days |
| Initial triage update | Within 5 business days |
| Severity confirmation | Within 10 business days, when feasible |
| Status updates | At meaningful milestones or at least every 15 business days for validated High/Critical reports |
| Closure notice | After remediation or documented resolution |
These are operational targets, not reward or payment commitments.
Coordinated Disclosure
FundWisr should work in good faith toward coordinated disclosure.
Timing should consider severity, exploitation, customer impact, remediation complexity, vendor dependencies, patch adoption, public safety, and researcher plans.
A typical coordination period may be up to 90 days, but actual timing should be risk based and mutually discussed.
Rewards and Recognition
FundWisr may choose to provide acknowledgment, hall-of-fame recognition, a letter of appreciation, a discretionary reward, or a bug-bounty payment.
No reward is owed unless FundWisr has published or separately agreed to a reward program.
FundWisr™ is operated by Impctrs Management Group, LLC under license from Mzrik Innovations, LLC. © 2026 Mzrik Innovations, LLC. All rights reserved. FundWisr™ and its proprietary frameworks, scoring systems, methodologies, platform content, software, and related intellectual property are owned by Mzrik Innovations, LLC. Technology developed by AI Arkitech, LLC.