ChromaWave LogoChromaWave

Vulnerability Disclosure Policy

Last Updated: October 6, 2026

ChromaWave Consulting welcomes reports of security vulnerabilities in the GoodPAW app and this website. This page explains how to report one, what we commit to in return, and the terms under which we consider good-faith security research authorized.

How to report a vulnerability

Email info@chromawaveconsulting.com with the subject line "Security vulnerability report". Please include:

  • The affected product and version — for example the GoodPAW app version and Android version, or the page URL on this website.
  • A description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it, with any proof-of-concept code, screenshots, or requests and responses.
  • How to contact you, and how you would like to be credited, if at all.

Please do not include other people's personal data in your report. If you came across any, tell us what kind of data it was rather than sending it.

In scope

  • The GoodPAW Android app and the backend services it uses.
  • This website, chromawaveconsulting.com.

Out of scope

  • Denial-of-service testing, or anything that degrades the availability of our products or services.
  • Social engineering, phishing, or physical attacks against our staff, offices, clients, or users.
  • Accessing, modifying, or deleting data that belongs to anyone other than you.
  • Spam, or automated scanning that generates high traffic.
  • Systems belonging to our clients, and third-party services we use — please report those to their owners.

What we commit to

  • We acknowledge your report within 5 business days.
  • We investigate, tell you whether we can confirm the issue, and keep you updated as we work on a fix.
  • We follow coordinated disclosure: we ask that you keep the details private until a fix is available or 90 days after your report, whichever comes first. If a fix needs longer, we will explain why and agree a new date with you.
  • For each confirmed vulnerability in scope, we publish a security advisory on our Security Advisories page and request a CVE ID.
  • We credit you in the advisory, unless you prefer to remain anonymous.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for it, and if a third party takes legal action against you over research that followed this policy, we will make it known that your work was authorized.

Good-faith research means that you:

  • Test only against accounts and data that you own.
  • Stop as soon as you have confirmed a vulnerability, and report it to us promptly.
  • Do not access, keep, or share more data than you need to demonstrate the issue.
  • Stay within the scope above.
  • Give us the time described above to fix the issue before disclosing it publicly.

Contact

Security reports: info@chromawaveconsulting.com. Machine-readable contact details are published at /.well-known/security.txt.