Vulnerability disclosure
Vulnerability disclosure
If you have found a security flaw in InMyWords or this website, we want to hear about it, and we will not take action against you for reporting it in good faith.
Who this covers
INT6 Ltd, a company registered in Scotland, number SC547705, trading as INT6, which builds and holds InMyWords. It covers app.inmywords.chat and inmywords.chat. It is reviewed once a year.
How to report
- Email us. Write to [email protected] with "Security" in the subject, or use the contact form.
- Say what you found. The address, what you did, what happened, and anything we need to see it ourselves.
- One report is enough. You do not need to have proved every consequence.
What we ask
- Do no harm. Do not read, change or delete anybody else's data beyond the least needed to show the flaw, and stop as soon as you reach any.
- Do not disrupt the service. No denial of service, no automated scanning at volume, no social engineering of our staff or customers.
- Give us time. Keep the details to yourself until we have fixed it, or until 90 days have passed, whichever is sooner.
What we do
- We reply. We acknowledge a report within five working days.
- We fix it. We tell you what we found and when it is fixed.
- We credit you. If you would like to be named when it is fixed, we will name you.
For software
The same details are published at /.well-known/security.txt.
Document control
- Reference
- IMW-POL-006
- Version
- 01
- Release date
- 2 October 2026
- Status
- Released