Vulnerability disclosure policy
For:Software and cybersecurity professionals
Assumes professional familiarity with software, networking, or cybersecurity concepts.Version 1.0 — Effective August 20, 2026
Exist.Dev LLC welcomes good-faith reports that help improve WolfP2P's security. This policy explains how to test responsibly, what is authorized, and how to send a report without putting users, data, or the service at unnecessary risk.
This policy concerns security vulnerabilities in WolfP2P. It is not the route for reporting a transferred file, ordinary support question, copyright complaint, privacy request, or an active emergency involving immediate danger.
How to report a vulnerability
Email info@exist.dev with WolfP2P security report in the subject line. Include only the information reasonably necessary to understand and reproduce the issue:
- the affected WolfP2P URL, feature, or component;
- the browser, operating system, and relevant version information;
- a clear description of the vulnerability and its likely impact;
- reproducible steps or a minimal proof of concept;
- the date and approximate time of relevant testing; and
- how Exist.Dev can contact you about remediation and coordinated disclosure.
Do not send transferred files, other people's information, credentials, private keys, authentication tokens, live tunnel codes, complete database contents, or unrelated personal information. Redact secrets and personal information from screenshots and logs.
Systems covered by this policy
This policy applies to the WolfP2P website and services operated by Exist.Dev under:
wolfp2p.comand itswwwredirect;- WolfP2P's public application, API, and signaling endpoints on that origin; and
- WolfP2P code and content delivered through those services.
Third-party products and infrastructure are not authorized by this policy. This includes browsers, browser extensions, operating systems, internet providers, Cloudflare, Microsoft Azure, and another person's device or network. Report a vulnerability in a third-party product to that provider unless the issue is specifically caused by WolfP2P's implementation or configuration.
Authorized good-faith testing
Security research is authorized under this policy when you:
- test only with devices, browsers, networks, files, tunnel invitations, and other resources you own or have explicit permission to use;
- create the minimum traffic and data needed to demonstrate the issue;
- respect rate limits and stop if testing may degrade the service;
- avoid accessing, changing, retaining, or disclosing another person's information;
- stop testing and report promptly if you encounter information that is not yours;
- avoid actions that could interrupt an active transfer or impair availability for another person; and
- give Exist.Dev a reasonable opportunity to investigate and remediate the issue before public disclosure.
If your research follows this policy, Exist.Dev will treat it as authorized and will not initiate legal action against you solely for that research. If a third party initiates legal action concerning research that complied with this policy, Exist.Dev may state that the activity was conducted under this authorization.
This authorization does not apply to conduct outside this policy, does not bind third parties, and does not excuse violations of another person's rights or applicable law. If you are uncertain whether a proposed test is authorized, ask before proceeding.
Prohibited testing
This policy does not authorize:
- denial-of-service, load, stress, or resource-exhaustion testing;
- attempts to guess or collect other people's tunnel codes or enter their tunnels;
- bypassing rate limits or using distributed sources to evade security controls;
- social engineering, phishing, impersonation, spam, or deceptive communication;
- physical attacks or testing of offices, personnel, or personal devices;
- malware deployment, persistence, destructive actions, or modification or deletion of data;
- accessing, downloading, copying, or retaining data beyond the minimum needed to demonstrate an issue involving your own test data;
- testing third-party systems without their authorization;
- automated scanning that creates excessive traffic or interferes with ordinary use; or
- public disclosure while an issue presents an active risk and before reasonable coordination has occurred.
Do not exploit a vulnerability to demonstrate additional impact after the issue has been established. Stop and report it.
What to expect after reporting
Exist.Dev aims to:
- acknowledge a report within seven business days;
- provide an initial assessment or request for necessary details within 14 business days;
- send a progress update at least every 30 days while a confirmed issue remains unresolved; and
- coordinate remediation and disclosure according to the issue's severity, exploitation risk, affected users, and dependencies.
These are response targets, not guarantees or service-level commitments. Complex issues and third-party dependencies may take longer. Exist.Dev may act sooner, restrict technical details, or notify affected people or authorities when required for safety, security, or legal compliance.
Coordinated disclosure
Please coordinate public disclosure with Exist.Dev. For an ordinary confirmed vulnerability, a target of up to 90 days after confirmation is generally reasonable, but the appropriate date may be shorter or longer depending on active exploitation, severity, remediation complexity, vendor coordination, and risks to users.
Exist.Dev does not currently offer a bug bounty or promise payment, employment, public recognition, or another reward. Any recognition requires the reporter's permission and must not expose information that would create additional risk.
Handling report information
Exist.Dev will use report information to investigate, remediate, document, and communicate about the security issue. It may share necessary information with service providers, professional advisers, affected parties, or authorities when reasonably necessary or legally required. Personal information is handled under the Privacy Notice.
Material public updates will be linked from WolfP2P Security when appropriate.
Contact
Security reports: info@exist.dev
Operator: Exist.Dev LLC
2769 Avalon Street
Cantonment, Florida 32533, United States