Responsible Disclosure Policy

One policy covering wedgewoodai.com and the WedgeWoodCloud sites. If you find a security weakness, tell us privately and we will work with you.

Last updated: 11 October 2026

The policy in short: if you find a security weakness in our websites or services, please tell us privately at [email protected]. Give us a fair chance to fix it before you tell anyone else. If you follow this policy in good faith, we will work with you, keep you informed and thank you publicly if you'd like. We will not take legal action against you.

1. Scope

In scope

  • wedgewoodcloud.co.nz and wedgewoodcloud.com, including Helen, our AI assistant
  • the WedgeWoodCloud platform (app.wedgewoodcloud.co.nz, once it's live)
  • wedgewoodai.com, including Wedge, its AI assistant, and the knowledge feed
  • Terraform code generated by WedgeWoodCloud, where a weakness comes from our generator

Out of scope

  • Our providers' platforms, such as Abacus.AI, Cloudflare and the cloud providers. Report those to the provider.
  • Our customers' own cloud environments. Never test them through us.
  • Denial-of-service or load testing, spam, social engineering, or physical attacks.
  • Low-impact findings with no real-world risk, such as missing headers on pages with no sensitive data, or clickjacking on pages with no actions.
  • Simply getting Helen or Wedge to say something odd. It is in scope if you get them to reveal their instructions or secrets, bypass their rules in a way that could harm someone, or reach data they shouldn't.

2. How to report

Email [email protected]. Please include:

  1. what you found, and where (the address or the feature)
  2. the steps to reproduce it
  3. what an attacker could do with it
  4. how we can contact you, and whether you'd like to be credited

Please don't include anyone else's personal information in your report. If you came across any, tell us what kind of data it was, but not the data itself.

If you don't hear back from us, you can also report through New Zealand's National Cyber Security Centre.

3. What we commit to

StepWhen
A person confirms we've received your reportWithin 1 week (5 working days)
We tell you whether we can reproduce it, and how serious we think it isWithin 3 weeks (15 working days)
We fix critical and high-severity issuesAs quickly as possible, aiming for 30 days
We fix other issuesAiming for 90 days
We agree with you when the issue can be made publicOnce it's fixed, usually within 90 days of your report

We don't send automated replies. Every response comes from a person who has checked your report first, so it takes a little longer, but what we tell you will be accurate.

We'll keep you updated along the way. If a fix will take longer, we'll tell you why. We don't currently offer payment for reports, but we're happy to credit you on our website.

4. Rules for testing

Please:

  • Only use your own accounts and test data. Never access, change or delete anyone else's information.
  • Stop as soon as you've shown the problem. If you reach personal or customer data, stop, don't keep it, and tell us.
  • Don't degrade the service. No automated scanning above normal browsing speed, and no attempts to run up our AI or cloud costs.
  • Keep it private until we've agreed it can be made public.

Our good-faith promise: if you follow these rules, we'll treat your research as authorised. We won't take legal action against you or ask anyone else to, and we'll make that clear if anyone else asks. This promise can't cover laws we don't control, or the platforms of the providers listed as out of scope.