Reporting a security problem

Last updated: 8 October 2026

Email contact@walterssentinel.com. Put "security" in the subject so it is not treated as an ordinary message. You will get a reply from a person within three working days, and we will tell you what we are doing about it.

There is no bounty. We are a small business and we would rather say that than imply one.

What we promise you

What we ask of you

What is in scope

Anything we run: walterssentinel.com and its subdomains, including the account hub, the app and every service subdomain, and our API.

What is not

What helps

Enough to reproduce it: the address, what you did, what happened, and what you expected instead. A short screen recording is often faster than a long description. If you have a suggested fix, say so - we will read it.

If what you found exposes somebody's data, say so in the first line rather than at the end. It changes what we do in the first hour.

Where this is published

The machine-readable version is at /.well-known/security.txt, in the format described by RFC 9116.

What we have, and what we do not

We think it is worth being plain about this rather than leaving it to be inferred. We hold no ISO 27001 certificate and no SOC 2 report. What we actually do to protect data is written out, measure by measure, in Annex 3 of our Data Processing Agreement, so that you can judge it rather than take our word for it.