Responsible Vulnerability Disclosure
Introduction
WallStreetBets takes the security of our systems and user data seriously. We value the contributions of security researchers and encourage responsible disclosure of any vulnerabilities that may be found in our service.
If you believe you have found a security vulnerability, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.
Disclosure Policy
When reporting vulnerabilities, please follow these guidelines:
- Report vulnerabilities to security@wallstreetbets.com. We will acknowledge receipt of your report within five business days.
- Allow reasonable time for us to address the issue before making any public disclosure. We aim to resolve critical issues within one week.
- Act in good faith by avoiding any actions that could violate privacy, destroy data, or disrupt our services. Only test against systems you own or have explicit permission to access.
Exclusions
The following activities are prohibited and should not be performed as part of security research:
- Distributed Denial of Service (DDoS) attacks or other denial of service attacks
- Spam or unsolicited bulk messaging
- Social engineering or phishing attacks against WallStreetBets staff or contractors
- Physical attacks against WallStreetBets infrastructure or data centers
Changes
We reserve the right to update these guidelines at any time. The most current version will always be available at this page.
Contact
For security inquiries, vulnerability reports, or questions about this policy, please contact us at security@wallstreetbets.com.