# WealthWise — Security contact information (RFC 9116) # https://securitytxt.org/ Contact: mailto:support@mywealthwise.ca Expires: 2027-05-18T00:00:00.000Z Preferred-Languages: en, fr Canonical: https://mywealthwise.ca/.well-known/security.txt Policy: https://mywealthwise.ca/privacy/ # If you've discovered a security vulnerability in our service, please email # us at the address above. Include steps to reproduce, the affected # endpoint or page, and your preferred contact method. We aim to acknowledge # all reports within 5 business days. # # Out of scope: # - Social engineering # - Physical attacks # - Attacks requiring physical access to a user's device # - DoS / volumetric attacks (please don't run these against us) # # In scope: # - XSS, CSRF, SSRF # - Authentication / authorization bypass # - Sensitive data exposure # - Server-side vulnerabilities in /api/* endpoints # - Issues affecting the cookie-consent + Google Ads gtag integration