Security & disclosure rafael.reis@wyrd-group.com
Security

Found something? We want it, signed and boring.

A company that sells proof should be easy to report a bug to. Write to rafael.reis@wyrd-group.com with reproduction steps; encrypted mail is welcome.

01
What exists today: a human reads every report. This mailbox is monitored manually, not yet by a staffed security team on a formal SLA clock. We aim to acknowledge within a few working days, but treat that as current practice, not a contracted guarantee, until the program below is formally staffed.
02
Coordinated disclosure — the norm we intend to hold to. Roughly 90 days is our working target, agreed with you case by case, extendable only for genuine remediation complexity. We credit reporters who want credit.
03
Good-faith research is safe. We will not pursue action against research that respects scope, avoids data exfiltration beyond proof-of-concept, and gives us reasonable time to fix.
04
In scope: this website, published Wyrd software artifacts, and pilot deployments you are authorized to test. Out of scope: social engineering, physical intrusion, denial of service, and third-party services we do not control.
05
No bounty program yet. We say so rather than imply one. Serious findings are taken seriously regardless.
What is not built yet — stated plainly

There is no dedicated, staffed security inbox with guaranteed response times, and no published /.well-known/security.txt or PGP key — that infrastructure ships alongside the first production deployment, not before it. Until then, rafael.reis@wyrd-group.com reaches a real person, on a best-effort basis, and this page is the whole policy — not a service-level commitment.