How we protect client systems, and how to report a vulnerability in good faith.
Security is core to what we sell. WarMachine33 (Delta-One Capital Sàrl, Geneva) designs and operates automations under Swiss data protection law (nLPD/nDSG) and GDPR. Key practices on this website:
X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and a restrictive Permissions-Policy.We welcome reports from security researchers acting in good faith. If you believe you have found a vulnerability affecting warmachine33.cloud or our services, please tell us before disclosing it publicly.
How to report: email [email protected] with a clear description, steps to reproduce, and any proof-of-concept. Encrypt sensitive details on request.
Our commitment:
In scope: warmachine33.cloud and its subdomains that we operate.
Out of scope / please avoid: denial-of-service, spam or social-engineering of staff or clients, physical attacks, automated scanning that degrades service, and any access to or modification of data that is not your own. Do not test third-party services (e.g. Stripe, hosting providers), report the integration point to us instead.
Machine-readable contact details are published at /.well-known/security.txt (RFC 9116).