Security and vulnerability disclosure
Last updated:
- Found a vulnerability? Email security@dragonwispr.com. We reply within 2 business days.
- Good-faith research that follows this policy is authorised. We will not take legal action against it.
- We ship security updates for the desktop app until at least 31 December 2031, and in any case for as long as the Service is offered.
1. How to report a vulnerability
Email security@dragonwispr.com in English or Greek. Please include what is affected (URL, endpoint or app version), the steps to reproduce it, the impact you think it has, and how we can credit you if you would like that. If you need an encrypted channel, say so in a first short email and we will set one up.
Our machine-readable contact details are at /.well-known/security.txt.
2. Scope
In scope
- The website at dragonwispr.com and the API at api.dragonwispr.com.
- The Dragon Wispr desktop app, latest released version.
- Our sign-in, account, billing integration and waitlist flows.
Out of scope
- Services run by our providers (for example Cloudflare, Supabase, Groq, Paddle). Please report those to the provider; tell us too if it affects our users.
- Denial-of-service or load testing, spam, social engineering, and physical attacks.
- Reports from automated scanners without a demonstrated, realistic impact.
- Issues that need a compromised device, a rooted or jailbroken system, or an outdated browser.
3. Rules for testing
- Use only accounts you own, and never access, change or delete other people’s data.
- If you reach personal data by accident, stop, do not keep a copy beyond what the report needs, and tell us.
- Do not degrade the Service for others, and stay within your plan’s normal usage.
- Give us reasonable time to fix the issue before you share it with anyone else.
4. Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorised. We will not take legal action against you or ask anyone else to, and we waive the parts of our Terms of Service that would otherwise restrict it (such as the ban on probing the Service). If a third party takes legal action against you for research that followed this policy, we will make clear that it was authorised. This policy cannot authorise testing of systems we do not own.
5. What you can expect from us
- Acknowledgement of your report within 2 business days.
- A first assessment, including severity, within 5 business days.
- A fix as fast as we can: our targets are 7 days for critical issues, 30 days for high and 90 days for the rest. We keep you updated until it is resolved.
- Coordinated disclosure: we agree a publication date with you, by default after the fix ships and at the latest 90 days after your report.
- Credit in our release notes or advisory, if you want it. We do not run a paid bug bounty at this time.
6. Support period and updates
We provide security updates for the Dragon Wispr desktop app until at least 31 December 2031, and in any case for as long as the Service is offered. Fixes are released for the latest released version of the desktop app, so please keep it up to date: we tell you about security updates by email and publish them on this website (built-in, signed automatic updates are planned). Security fixes are delivered separately from new features where possible and are always free of charge. If we ever decide to end support, we will announce the end date at least 12 months in advance.
We generate a software bill of materials (SBOM) for the desktop app on every change, will publish it with each public release and keep it for at least 10 years, and we monitor the components we use for known vulnerabilities.
7. Incidents
If a vulnerability in the app is actively exploited, or a severe incident affects its security, we notify the authorities through the EU single reporting platform under the Cyber Resilience Act (an early warning within 24 hours and a full notification within 72 hours) and inform affected users, with steps to protect themselves, without undue delay. If personal data is affected, we also notify the Hellenic Data Protection Authority within 72 hours where required, as described in our Privacy Policy.