The Wholesale NetworkThe Wholesale Network

Vulnerability Disclosure Policy

Last updated September 3, 2026

The Wholesale Networktakes the security of our customers' data seriously. If you believe you have found a security vulnerability in our systems, we want to hear about it. This policy explains what you may test, how to report what you find, and what you can expect from us in return.

Scope

This policy covers:

  • The The Wholesale Network web application at https://twnos.com
  • Our public API serving that application

Anything not listed above is out of scope, including our marketing pages, third-party services we use (email delivery, hosting, analytics) and the software those vendors run. Vulnerabilities in a third-party product should be reported to that vendor under their own disclosure policy. If you are unsure whether something is in scope, ask us before you start.

Safe harbour

If you make a good-faith effort to follow this policy during your research, we will treat your work as authorised. We will not pursue or support legal action against you for accidental, good-faith violations, and we will make it known that your actions were authorised if a third party raises a concern. This does not extend to research that goes outside the scope above or ignores the limits in the next section.

What we ask of you

  • Report anything you find promptly, and give us reasonable time to fix it before disclosing publicly.
  • Use only your own test accounts and data. Do not access, modify or delete data belonging to anyone else.
  • Use an exploit only as far as needed to confirm a vulnerability exists. Do not use it to extract data, establish persistence, or move to other systems.
  • If you encounter personal data, customer email content or credentials, stop immediately, do not save a copy, tell us, and treat what you saw as confidential.
  • Do not degrade the service for our customers, and do not submit large volumes of low-quality reports.

Testing that is not authorised

  • Denial-of-service testing of any kind, including volumetric or resource-exhaustion attacks
  • Social engineering, phishing or pretexting against our staff, customers or vendors
  • Physical attempts against offices, hardware or personnel
  • Automated scanning heavy enough to affect availability for other users

How to report

Email [email protected] with "Security" in the subject line. Reports may be submitted anonymously. Please write in English where you can, and include:

  • What the vulnerability is, and where you found it (the URL or endpoint)
  • What an attacker could do with it
  • Step-by-step instructions to reproduce it, with screenshots or a proof of concept if you have one

What you can expect from us

  • We will acknowledge your report within three business days.
  • We will tell you whether we have confirmed the issue, and keep you updated as we work on a fix.
  • We will let you know when it is resolved.
  • We are happy to discuss your findings, and to credit you when we publish a fix if you would like us to.

We do not currently operate a paid bug bounty programme, so reports are not eligible for a monetary reward.

Contact

Security reports and questions about this policy: [email protected].