WALLBED KING 窩居·家
🔒 Security & disclosure

If you find a bug, here's how to tell us.

A static website serving customer photos and contracts has real security responsibilities. This page is the public policy for how we run it and the responsible-disclosure path if you spot a problem.

· security@wallbedking.com.hk

This site is hand-built static HTML. There is no admin login, no database, no CMS. That removes most of the typical website attack surface — but not all. Below is what we do, what we don't yet do, and how to report something we missed.

1. What we do today

2. What we don't yet do

3. Responsible disclosure — how to report a bug

  1. Email security@wallbedking.com.hk with the subject line "SECURITY" + a one-line summary.
  2. Describe what you found, the URL/file, and ideally a proof-of-concept.
  3. We will acknowledge within 1 working day.
  4. We will provide a fix ETA within 5 working days. Critical issues (information disclosure of customer data, content injection) get same-day attention.
  5. You can request public credit when we publish the fix in the Trust Scorecard "what we got wrong" section. We will not threaten or restrict legitimate security research.

4. Out of scope

5. security.txt

The standard /.well-known/security.txt file linking to this page is on the roadmap. Until it's deployed, this page is the canonical reference and the email address above is the contact.

Found something?

Email security@. Acknowledged within 1 working day. We'll work with you, not against you.

📧 security@wallbedking.com.hk