Skip to main content 跳到主内容
WideWired 网连网络
Security

Security Policy

Last updated: 2026-09-15

WideWired takes the security of its services and clients seriously. This page is the entry point for reporting suspected vulnerabilities. The machine-readable version of this policy is published at /.well-known/security.txt per RFC 9116.

1. Reporting a Vulnerability

Please report suspected vulnerabilities through one of the channels below.

Please do not disclose security matters in public venues such as social media or public forums. Public reports will be redirected to the address above before triage begins.

2. Sensitive Material

Please keep the initial report to the minimum detail needed for triage and avoid sending secrets, private keys, customer data, or exploit payloads that are not required to understand the issue. If sensitive supporting material is necessary, contact us first at security@widewired.com so we can arrange an appropriate secure channel.

3. What to Include

A useful report contains:

4. Disclosure Window

We follow coordinated disclosure. By default we ask reporters to keep the finding confidential until a fix is shipped, or for up to 90 days from the acknowledgement date, whichever comes first. Extensions are negotiated by email.

5. Response SLA

Vulnerability response SLA: stage and target timeline.
StageTarget
First acknowledgementwithin 72 hours
Triage and severity assignmentwithin 7 days
Fix for critical severitywithin 30 days
Fix for high severitywithin 60 days
Fix for medium or low severitywithin 90 days

Severity is decided per the matrix in our internal vulnerability disclosure policy. Critical covers RCE on backend services, fleet private-key compromise, account takeover, and billing bypass.

6. Scope

In scope.

Out of scope.

7. Safe Harbor

We will not pursue legal action or technical retaliation against researchers who act in good faith and within this policy. Good faith means:

A report that breaches any of the above falls outside safe harbor.

8. Recognition

After a fix is shipped, we credit reporters (with their consent) on our Hall of Fame. Anonymous acknowledgement is available on request.

9. Contact

Security reports: security@widewired.com. For non-security questions, see the Contact page.

安全

安全策略

最近更新:2026-09-15

网连网络(WideWired)十分重视服务与客户端的安全。本页面是上报疑似漏洞的入口。本策略的机读版本依据 RFC 9116 发布在 /.well-known/security.txt

1. 上报漏洞

请通过下列任一渠道上报疑似漏洞。

请勿在社交媒体、公开论坛等公开场合发布安全相关内容。公开上报会被引导至上述渠道后再进行分诊。

2. 敏感材料

初次上报请只包含分诊所需的最少信息,避免发送不必要的 secret、私钥、客户数据或利用载荷。确需补充敏感材料时,请先通过 security@widewired.com 联系我们,以便安排合适的安全通道。

3. 报告内容建议

一份有效的上报通常包含:

4. 披露窗口

我们采用协同披露。默认请求上报者在修复发布前、或自确认日起 90 天内(以先到为准)对该发现保密;可通过邮件协商延期。

5. 响应 SLA

漏洞响应 SLA:阶段与目标时限。
阶段目标
首次确认72 小时内
分诊及严重性评级7 天内
严重级修复30 天内
高级修复60 天内
中、低级修复90 天内

严重性按我们内部漏洞披露规范中的矩阵判定。严重级覆盖:后端服务上的 RCE、fleet 私钥泄露、任意账号接管,以及计费旁路。

6. 范围

纳入范围。

不在范围。

7. 安全港承诺

对于在本策略框架内、出于善意进行研究的安全研究员,我们承诺不提起诉讼,也不进行技术对抗。善意的边界包括:

任一项不满足,即不在安全港范围内。

8. 致谢

修复发布后,经报告者授权,我们会将其登记在 致谢名录。也可应请求匿名致谢。

9. 联系方式

安全相关:security@widewired.com。非安全类问题请前往 联系我们 页面。