Security and disclosure

A safe way to start a sensitive conversation.

Use this page to request a protected channel for assessment material or to report a possible weakness in a WebCook-operated system.

This page does not authorize testing. If you encounter a possible issue, stop once you have enough evidence to explain it and contact us.

Secure communications

Start with a short, non-sensitive email. Tell us who you are, the organization involved, the general subject and how you would prefer to continue. Do not attach evidence or credentials to that first message.

If the conversation needs protection beyond ordinary email, we will verify the participants and agree on a suitable channel before anything sensitive is exchanged. This site does not publish a standing encryption key or messaging identity; do not trust contact details that appear only in an unsolicited message.

Include in the first email

  • Your name and organization
  • A non-sensitive description of the system
  • Why you are getting in touch
  • Your preferred way to continue

Hold until the channel is agreed

  • Credentials, tokens or private keys
  • Customer or employee information
  • Private source code or architecture
  • Working exploits or raw evidence
Request a secure channel

Report a possible vulnerability

Email [email protected] with the subject “WebCook security report.” Include the affected WebCook product or domain and a brief, non-sensitive summary. We will confirm that the system is ours and arrange how to receive supporting evidence.

Do not send working credentials by ordinary email, access another person’s data or publish an unpatched issue. A report is not authorization to continue testing.

Systems covered by this contact

WebCook-operated websites, the private-beta WebCook testing platform and released WebCook client software. Customer environments, third-party services and look-alike domains are not covered.

Testing requires written authorization

WebCook Labs tests only within a written, agreed scope. Before work begins, that authorization identifies the systems, dates, permitted techniques, evidence limits and emergency contacts.

Without that agreement, do not degrade a service, use social engineering, retain unrelated information or take any action beyond what is necessary to describe a possible issue safely.

Company and personnel

WebCook Labs is the security-testing practice of WebCook Technologies LLC, a Delaware limited liability company. Our operations and employees are entirely based in the United States, and all employees undergo background checks.

Engagement-specific access, communication channels, evidence handling and retention are agreed in writing before testing begins. Ask us about the controls relevant to your scope during intake.

Handling assessment material

Each engagement defines how credentials, test data, evidence and reports are transferred, stored and retained. We use the client-approved channel where one is required and collect only what is needed to demonstrate a finding safely.

Questions about a planned assessment can begin on the contact page. Keep the first message non-sensitive.