Annual billing, no setup fee.
See pricing →Check your eligibility for the Jumpstart programme.
Check my eligibility →The guide to frame a first project.
Read the guide →We welcome security researchers who help us keep our products safe. This policy explains what you may test, how to report a vulnerability, what you can expect from us in return, and the legal protection we offer for research carried out in good faith.
This program enables users and security researchers to submit vulnerabilities to Witivio on products within the scope of the program (see the "Scope" section). These submissions provide a chance to win awards in amounts to be determined by Witivio in its own discretion.
Reports received through this program are handled inside Witivio's ISO/IEC 27001:2022 certified information security management system. They are recorded as security events, triaged through our technical vulnerability management process, and tracked through to closure.
Witivio may change or cancel this Program at any time and for any reason. Similarly, these conditions may change at any time and will become applicable upon publication of the new version. The version in force on the day you submit a report is the one that applies to that report. By participating in the program, you automatically agree to the applicable terms and conditions.
Witivio considers security research carried out in accordance with this policy to be authorised, useful and conducted in good faith. Provided that you comply with this policy at all times:
This protection covers only the systems listed as in scope below, and only the actions strictly necessary to identify and demonstrate a vulnerability. It does not extend to third-party systems, and it cannot waive the rights of our customers, our suppliers or any other third party. Nothing in this section releases you from your obligations under applicable law, in particular data protection law. If you are unsure whether a given action is permitted, ask us at dpo@witivio.com before you carry it out.
The scope is limited to:
Anything not listed above is out of scope. That includes, in particular, the third-party services and platforms we rely on, systems belonging to our customers or partners, employee devices and accounts, and our physical premises. If you believe you have found a serious issue outside this scope, you may still tell us about it, but it will not qualify for a reward.
Protecting the personal data and confidential information entrusted to us is a condition of taking part, not a formality. When testing:
Where the platform allows it, use a recognisable user agent or a distinctive marker in your test traffic, so that our teams can tell your research apart from a real attack.
Witivio employees or former employees who left the company less than a year ago are not eligible for a reward. Likewise, the close entourage of employees is not eligible for a reward.
You must also be legally able to enter into this agreement and to issue a valid invoice, and you must not be located in, or acting on behalf of anyone in, a country or entity subject to applicable financial sanctions or export restrictions. If you are a minor, we will ask for the written consent of your legal guardian before paying any reward.
If you think you've found a vulnerability in the scope described above, please send it to: dpo@witivio.com
Send one vulnerability per email, write in English or in French, and use a clear subject line. The submission must contain:
After the reception, we will study the eligibility of the vulnerability. The time may vary depending on the type of vulnerability. We will tell you the outcome of our assessment, keep you informed as the fix progresses, and let you know once the issue is resolved. In return, we ask that you stay reachable and answer our questions if we need clarification to reproduce the finding.
Severity is assessed on the demonstrated impact on the confidentiality, integrity and availability of the affected system and of the data it holds, using the CVSS scoring system as a guide. Eligibility is entirely at our discretion and will not be subject to appeal.
If a vulnerability is raised by multiple people, only the first one raised will be eligible for a reward, the others will be classified as "duplicate". Several reports that trace back to the same root cause are treated as a single vulnerability.
Reported vulnerabilities must not be disclosed publicly unless expressly authorized by Witivio. In case of publication without this agreement, no reward will be given and legal proceedings may be initiated.
If a vulnerability is submitted in compliance with the previously defined clauses, a reward is possible. Rewards are discretionary: the amount reflects the severity of the issue, its real impact and the quality of the report, and the decision rests with Witivio alone.
For all payments, an invoice is required.
The invoice must be made out to Witivio, 16A Rue de Selestat, 68000 Colmar, France, and include all the requisite information as detailed below, including your name, address, IBAN, and VAT number (if applicable), as well as a short description of service.
Payments are made via bank transfer via IBAN only, it will be made only if the bank details have been transmitted.
Payment is made within 30 days after validation and provision of the invoice.
You remain solely responsible for declaring the reward to your tax authority and for meeting any tax or social security obligations that apply to you in your country of residence.
Every question about this policy, and every vulnerability report, goes to dpo@witivio.com. Please do not use our support channels or social media to report a security issue.