Security

Responsible disclosure policy.

If you've found a security vulnerability in Guardian Gaze or guardiangaze.com, we want to hear from you. Please read this policy before reporting.

Last updated: 1 January 2026

We welcome security disclosures

RedSecLabs is a security research firm. We take vulnerability reports seriously, respond promptly, and credit researchers who help us improve Guardian Gaze.

Scope

In scope:

  • The Guardian Gaze WordPress plugin (current and prior major releases)
  • guardiangaze.com (web application and API)
  • Authentication and account management systems

Out of scope:

  • Vulnerabilities in WordPress core, third-party plugins, or themes
  • Social engineering attacks against our staff
  • Physical security
  • Denial-of-service attacks
  • Automated scanning results without manual verification

How to report

Email your findings to [email protected]. Please include:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code or screenshots
  • Your name or handle (if you want credit)

Please encrypt sensitive reports using our PGP key, available on request.

What we ask

  • Act in good faith and do not access data beyond what is necessary to demonstrate the vulnerability
  • Do not disclose the issue publicly until we've had a reasonable time to fix it
  • Do not use the vulnerability to attack real users or live systems
  • Comply with applicable laws throughout your research

What we promise

  • 48-hour acknowledgement of your report during UK working hours
  • Regular communication on progress toward a fix
  • Public credit in our release notes and this page (if you want it)
  • A 90-day disclosure window before we publish details publicly
  • Safe harbour: we will not pursue legal action against good-faith researchers

Safe harbour

We consider security research conducted under this policy to constitute authorised activity. If legal action is initiated by a third party against you for research conducted under this policy, we will make our authorisation known. We ask that you contact us before engaging in research that might be otherwise illegal in your jurisdiction.

Hall of fame

We publicly recognise researchers who responsibly disclose qualifying vulnerabilities. If you'd like to be listed, include your preferred name or handle in your report.

Contact

[email protected], for vulnerability reports and security questions.

For WordPress.org security issues, see wordpress.org/about/security/.