WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

Security & brandEffective September 8, 2026Version 3.1

Vulnerability Disclosure Policy

We want to hear about security problems in our products. This policy tells you how to report one, what we will do, what we ask of you, and the legal protection we offer if you follow it.

Report to security@workmonitor.ai. That mailbox is monitored, and a report to it starts the process below.

We do not currently operate a paid bug-bounty programme. We say so at the top rather than letting you find out after the work. We do credit researchers who want to be credited.

01

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat that research as authorized, and specifically:

  • We will not bring or support a legal claim against you in connection with it, including under the US Computer Fraud and Abuse Act, state computer-crime statutes, the UK Computer Misuse Act, or equivalent laws elsewhere.
  • We will not bring a claim under the anti-circumvention provisions of the Digital Millennium Copyright Act, or its equivalents, for circumventing a technical measure in the course of that research.
  • We waive, for that research, the provisions of our Acceptable Use Policy and Website Terms of Use that prohibit probing, scanning and testing the security of our systems.
  • If a third party brings a claim against you for research conducted in compliance with this policy, we will make it known that your activity was authorized.
  • This protection applies to you personally and to the organization you are acting for. It is not conditional on the finding being valid, on the report being novel, or on us agreeing with your severity assessment.
  • If you are unsure whether something is in scope, ask us at security@workmonitor.ai before you test. A good-faith question, and a good-faith mistake about scope that you disclose promptly and stop on request, are covered.
  • Safe harbour does not extend to conduct outside this policy, including extortion, deliberate destruction, exfiltrating data beyond what is needed to demonstrate the issue, or continuing to access systems after we have asked you to stop.
02

What is in scope

Systems we operate: workmonitor.ai and its subdomains, the WorkMonitor web application, the public API, the certificate verifier, our desktop agents for Windows, macOS and Linux, and our browser and editor extensions.

Test only against an account you own or have written permission to test. Create a free account for testing rather than using someone else's.

03

What is out of scope

Do not test any of the following. Reports about them are welcome as information, but they are not treated as vulnerabilities and safe harbour does not authorize testing them.

  • Any customer's account, organization or data that is not yours, and any device belonging to a monitored worker.
  • Systems operated by our sub-processors or by third parties. Report those to their owners under their own policies.
  • Denial-of-service testing, load testing, resource-exhaustion testing, or anything that degrades the service for others.
  • Physical attacks, social engineering of our staff or customers, phishing, and attacks on our people's personal accounts or devices.
  • Spam, mass-mailing our systems, or automated scanning at a volume that behaves like an attack.
  • Findings we generally consider low or non-issues, unless you can demonstrate real impact: missing security headers with no exploit path, reports generated solely by an automated scanner, weak TLS configuration on a host that serves no sensitive content, self-XSS, missing rate limits on an endpoint that carries no sensitive action, clickjacking on a page with no state-changing control, email configuration findings such as SPF, DKIM or DMARC, version-disclosure banners, and enumeration that does not disclose personal data.
04

What we ask of you

The rules that make this work for both of us.

  • Access only the minimum data needed to demonstrate the issue. The moment you can see that you have access to data you should not have, stop.
  • Do not read, copy, retain, modify or delete anyone else's data. If you encounter personal data, stop, do not save it, and tell us in the report that you encountered it.
  • Do not degrade, disrupt or interrupt the service.
  • Do not install a backdoor, leave a persistent artefact, or maintain access after you have demonstrated the issue.
  • Give us reasonable time to fix the issue before you disclose it publicly. Our default is 90 days from our acknowledgement, and we will agree a different period with you where the issue warrants it.
  • Do not use the finding for extortion, and do not condition disclosure on a payment. A report that arrives with a demand is not a security report and is handled as a threat.
  • Comply with the law, and with data-protection law in particular.
05

How to report

Email security@workmonitor.ai with enough detail for us to reproduce the issue: the affected component and URL, the steps, the request and response where relevant, a proof of concept, and your assessment of the impact.

Tell us whether you want to be credited, and under what name.

Do not report a vulnerability through the support messenger, the contact form, a public repository issue, or social media. Those routes are not confidential and put the issue in front of the wrong people first.

If you need to send us something sensitive, say so in your first message and we will arrange an encrypted channel.

06

What we will do

We will acknowledge your report within 2 business days.

We will give you an initial assessment, including whether we consider it a vulnerability and our severity view, within 10 business days.

We will keep you informed of progress at reasonable intervals, and tell you when it is fixed.

We aim to remediate on these targets, measured from confirmation: critical within 7 days, high within 30 days, medium within 90 days, low at the next convenient release. Where we cannot meet a target we will tell you why and give you a revised date.

We will not take legal action against you, and we will not ask your employer to.

Where an issue affected customer data, we will handle notification under our Data Processing Addendum and our incident-response plan. We will not name you in a customer notice without your agreement.

07

Credit

We are glad to credit researchers who want it, and we will name you in the fix announcement or in an acknowledgements list. Tell us how you want to be named.

You may say publicly that you reported an issue to us and that it was fixed, after it has been fixed and the disclosure period has passed. Please do not publish details that would help someone attack customers who have not yet updated a desktop agent.

08

No bounty, stated plainly

We do not currently pay for vulnerability reports. There is no bounty table, no swag programme and no tiered payout, and we would rather you knew that before you spent a weekend on our stack.

If we introduce a paid programme, we will announce it here and in our Legal Change Log. Reports made before then will not be retroactively eligible.

09

Contact

Security reports: security@workmonitor.ai.

Questions about this policy: security@workmonitor.ai or legal@workmonitor.ai.

By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

Questions about this document:legal@workmonitor.aiBack to the register