Scope
World AI Governance (WAIG) Foundation welcomes good-faith security research on publicly reachable digital properties we operate (websites, APIs, and authenticated portals we own).
How to report
Email security@waigfoundation.org with:
- Detailed reproduction steps
- Affected URLs, versions, or components
- Impact assessment and suggested severity
- Your contact details for follow-up
PGP key available on request.
Response SLA
- Critical — acknowledgment within 24 hours
- High — acknowledgment within 72 hours
- Standard — acknowledgment within 7 business days with a remediation timeline
Safe harbor
Good-faith research conducted within scope will not face legal action from WAIG Foundation. Do not access participant or learner data, disrupt production services, or exfiltrate personal information.
Out of scope
- Social engineering of staff or members
- Physical intrusion
- Denial-of-service or volumetric testing without prior written approval
- Testing third-party systems not operated by WAIG Foundation
Recognition
We appreciate coordinated disclosure. Public credit may be offered when mutually agreed and after remediation.
Contact
security@waigfoundation.org