Legal
Security
Last reviewed: internal draft, pending legal sign-off
Our approach
Security work at Warmbytes — for clients and for our own systems, including this site — is mapped against relevant security requirements and general secure-engineering practice. Warmbytes does not hold or claim PCI DSS, ISO 27001, or any other certification, and no regulatory approval is claimed anywhere on this site.
This website
This site enforces a nonce-based Content Security Policy with no unsafe-inline and no unsafe-eval for scripts, sends Referrer-Policy, X-Content-Type-Options, X-Frame-Options and a Permissions-Policy restricting camera, microphone and geolocation, and validates and rate limits contact-form submissions server-side.
Responsible disclosure
If you believe you’ve found a security vulnerability in this website, we want to hear about it. Please report it to hello@warmbytes.com with:
- A description of the issue and its potential impact
- Steps to reproduce it
- Any proof-of-concept material needed to understand it
We ask that you avoid accessing, modifying or deleting data that isn’t yours, avoid degrading service for other visitors, and give us a reasonable opportunity to investigate and address a report before disclosing it publicly. We will acknowledge a good-faith report and keep you informed as we work through it. Warmbytes does not currently operate a paid bug-bounty program, and this scope covers this website only — vulnerabilities in a client’s own production systems are handled under that client’s own disclosure process, not this one.
Contact
For anything else security-related, reach us at hello@warmbytes.com.