Reporting a security problem
Last updated: 8 October 2026
Email contact@walterssentinel.com. Put "security" in the subject so it is not treated as an ordinary message. You will get a reply from a person within three working days, and we will tell you what we are doing about it.
There is no bounty. We are a small business and we would rather say that than imply one.
What we promise you
- We will not take legal action against you, or ask anybody else to, for research carried out in line with this page - including work that turns out to find nothing.
- We will reply, and keep replying, rather than going quiet once we have the details.
- We will fix what matters quickly, and tell you when it is done.
- We will credit you by name when we announce a fix, if you want that, and leave you out of it if you do not.
- We will not require you to sign anything, or to agree to stay silent for ever, as a condition of any of this.
What we ask of you
- Use your own account and your own test data. If you need an account, make one - sign-up is free.
- Stop as soon as you have proof. Do not read, copy, change or delete anybody else's data, and tell us at once if you see any by accident.
- Do not degrade the service for other people: no denial of service, no load testing, no bulk automated scanning.
- Do not use social engineering, phishing, or anything physical against us, our customers or our suppliers.
- Give us a reasonable chance to fix it before telling anybody else. We will agree a date with you rather than ask you to wait indefinitely.
What is in scope
Anything we run: walterssentinel.com and its subdomains, including the account hub, the app and every service subdomain, and our API.
What is not
- Our suppliers' own systems - Stripe, Microsoft, Amazon, Oracle, Turso and the rest. Their disclosure programmes are the right route, and they are listed on our sub-processor page.
- Findings from an automated scanner with nothing behind them - a missing header or a TLS configuration preference, with no way to use it for anything.
- Things that need a device already compromised, or a person already signed in on it.
- Our customers' own websites, which we monitor on their behalf but do not run.
What helps
Enough to reproduce it: the address, what you did, what happened, and what you expected instead. A short screen recording is often faster than a long description. If you have a suggested fix, say so - we will read it.
If what you found exposes somebody's data, say so in the first line rather than at the end. It changes what we do in the first hour.
Where this is published
The machine-readable version is at /.well-known/security.txt, in the format described by RFC 9116.
What we have, and what we do not
We think it is worth being plain about this rather than leaving it to be inferred. We hold no ISO 27001 certificate and no SOC 2 report. What we actually do to protect data is written out, measure by measure, in Annex 3 of our Data Processing Agreement, so that you can judge it rather than take our word for it.