Manawaroa

Product Security Policy

How to report a security problem in this website or in software we built, and what we do with the report. We acknowledge reports within 3 business days and work with the client who owns the affected software.

Effective October 7, 2026

  1. 01What this covers

    This policy covers this website and the software Manawaroa builds and delivers for clients.

    Our clients own that software and run it on their own systems. When a problem is in client software, we work with that client, and the client decides when to update its systems and what to tell its own users.

  2. 02Reporting a vulnerability

    Email security@manawaroa.io. Please include:

    • What is affected: a URL, a product name, or a repository
    • The steps to reproduce the problem
    • What an attacker could do with it
    • How you would like to be credited, if at all
  3. 03Testing in good faith

    Look only at as much data as you need to show the problem, and do not keep or share it. Do not degrade service for other people. Do not test systems that belong to our clients unless the client has given you permission. Give us a reasonable chance to fix a problem before you publish it.

  4. 04What happens after you report

    We acknowledge every report within 3 business days. We then confirm the problem, rate its severity with the Common Vulnerability Scoring System (CVSS), and tell you what we found.

    If the problem is in software we delivered to a client, we tell that client and work out the fix together. The client decides how and when the fix is released.

    We fix the most severe problems first. Timing depends on severity, on who owns the affected system, and on how the fix has to be released.

  5. 05Disclosure and credit

    We agree a disclosure date with you and, where client software is involved, with the client. We do not publish exploit code. If you want credit, we name you when the problem is disclosed.

  6. 06How we build

    A senior engineer reviews every change before it is delivered, including changes AI tools helped write. We use only the access to your systems that the work needs and give it back at handover.

    Our Responsible AI statement explains how your code and data are handled by AI tools.

  7. 07Limits

    No software is free of security problems, and we cannot promise that every reported issue will be fixed or fixed by a particular date. This policy does not give anyone permission to access systems or data they are not authorized to use.