Snapshot 20969
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security Responsible disclosure policy Found a vulnerability in SemantiqWall? Thank you for letting us know. Good-faith security research within these rules is authorized and welcome. How to report Email [email protected] with steps to reproduce, the impact you observed and, if you have one, a proof of concept. /.well-known/security.txt Scope The website and dashboard at semantiqwall.com, the API used by customers' agents and the SemantiqWall PHP and TypeScript SDKs. Out of scope: third-party services we use (hosting, email) and our customers' systems. Our timelines We acknowledge your report within 3 business days, keep you informed until it's fixed and agree on the disclosure date with you. Testing rules Don't access, change, or delete other organizations' data; use only your own accounts. Don't run tests that take the service down (DoS), and don't use social engineering on our team or customers. Stop and tell us as soon as you confirm the flaw; don't keep access or copy data beyond what's needed to demonstrate it. Give us a reasonable amount of time to fix the issue before disclosing it publicly. If you act in good faith within these rules, we won't take legal action against you, and we'll publicly credit your contribution if you'd like. Security advisories and CVEs When a critical or high-severity flaw affects customers, we publish an advisory on this page after the fix, with the weakness type (CWE), what was affected, since when and what customers need to do. When the flaw is in something customers install (the SDKs), or whenever the CVE program rules call for it, we request a CVE ID and provide accurate CWE and CPE fields. Advisories published so far: none. See how SemantiqWall follows CISA's Secure by Design goals See our security program policies in the Trust Center