Vulnerability Disclosure Policy
EN · RO
Last updated: October 8, 2026
Objective Online Company S.R.L. welcomes confidential reports that help protect WorkStudio users. Send reports to mail@workstudio.online with “Security report” in the subject, in English or Romanian. You may report without giving your name.
Scope and permitted testing
This policy covers the WorkStudio web application at https://www.workstudio.online and https://workstudio.online, including its first-party app and API routes. Other hostnames, email systems, infrastructure administration, and third-party services are excluded unless we give written permission. A link from WorkStudio does not put a provider in scope.
Use only accounts and data you control, with minimal requests needed to demonstrate a problem. Two accounts you control may be used to check separation. Do not test other users’ accounts, change their data, disrupt availability, send unwanted emails, make payments, incur AI/provider charges, use phishing or stolen credentials, guess passwords, or perform high-volume scanning. Stop when you have enough evidence. Contact us first if you are unsure whether a test is permitted.
If you encounter private data
Stop immediately. Do not explore, download, retain, or disclose other people’s data or secrets. Tell us the affected URL, time and minimal non-sensitive evidence. Do not include passwords, tokens, full documents or personal data in the initial email; ask us to arrange a suitable way to share sensitive evidence if needed.
What to report and how we respond
Include the affected URL or feature, reproducible steps using your own test data, expected and actual behavior, likely impact, and a redacted example. We aim to acknowledge security reports within one business day where reasonably possible, investigate according to impact, and keep the reporter informed of material progress. This is a response target, not a guaranteed resolution deadline. If you receive no acknowledgment, follow up using the same email address.
Good-faith research and disclosure
We authorize research within this policy’s scope and conditions. For research conducted in a good-faith effort to follow this policy, we will not initiate or support legal action by us solely because of that research. If a mistake or accidental data exposure occurs, stop and report it promptly so we can resolve it together. We cannot grant permission on behalf of third parties, bind authorities, or waive laws or other people’s rights.
Please coordinate public disclosure with us and allow reasonable time to protect users. We will discuss a disclosure date based on the risk and remediation progress; any extension should be agreed, not indefinite. Do not publish personal data or secrets. Researcher credit requires the researcher’s agreement. This is not a paid bug-bounty program and creates no entitlement to payment. Reports and contact details are handled under our Privacy Policy. If the language versions differ, Romanian prevails, subject to mandatory law.