Security Policy
Weyed is operated by Trailsafe Pty Ltd (Australia). This document explains how to report a security issue and what to expect in response.
Scope
Weyed is a continuously deployed platform, not a versioned software release. There is no supported-version matrix — the currently deployed API, the currently published web dashboards, and the most recent published builds of the mobile app are what is supported. Older mobile builds are superseded by updates and are not separately patched.
In scope
- The Weyed API
- The agent and transport-company web dashboards
- The Weyed mobile applications (iOS and Android)
Out of scope
- Third-party services we depend on (report those to the vendor directly)
- Denial-of-service testing, load testing, or anything degrading service for real users
- Social engineering of staff, contractors or customers
- Physical security
- Findings from automated scanners without a demonstrated impact
Reporting a vulnerability
Email security@weyed.com.au with:
- What you found and where
- Steps to reproduce, or a proof of concept
- What an attacker could achieve with it
Please report privately and give us reasonable time to fix the issue before disclosing it publicly.
What to expect
- Acknowledgement within 5 business days
- An assessment and our intended action within 15 business days
- An update when the issue is resolved, and credit if you would like it
We are a small team. These are commitments we can keep rather than aspirational ones, and we would rather be accurate than fast on paper.
Safe harbour
If you make a good-faith effort to comply with this policy while researching a vulnerability, we will not pursue legal action against you, and we will work with you to understand and resolve the issue quickly.
Good faith means: report promptly, do not access, modify or delete data belonging to anyone else, do not degrade the service for real users, and do not retain any data you encounter. If you access customer data accidentally, stop, tell us, and delete it.
No bug bounty
We do not currently run a paid bug bounty programme. We are grateful for reports regardless, and will credit reporters who want to be named.
Handling of personal data
Weyed processes personal information including location data. If your research brings you into contact with it, treat the safe harbour conditions above as binding — accessing another person's location history is not in scope under any framing.