Whale TV is committed to ensuring the security of its products and services and to protecting the interests of our customers and users.
Whale TV supports responsible security research and coordinated vulnerability disclosure. We encourage security researchers, customers, partners and other parties to report potential security vulnerabilities so that we can investigate and address them appropriately.
This Policy applies to vulnerability reports concerning all Whale TV products with digital elements and public-facing websites, applications, APIs, cloud services, and software or firmware versions that Whale TV owns, operates, or controls. Customer, partner, and third-party environments are outside this scope unless expressly stated otherwise.
This Policy does not by itself authorize testing. Researchers must obtain any authorization required by applicable law and the relevant system owner before conducting security testing.
Potential security vulnerabilities should be reported through:
Security Reporting Contact: cybersecurity@whaletv.com
Where possible, please provide the following information:
Please provide only the information necessary to help us understand and verify the vulnerability.
Do not include passwords, private keys, personal data, customer data or other unnecessary sensitive information in your report. If sensitive information is necessary for investigation, Whale TV may provide an appropriate secure method for sharing it.
Whale TV accepts anonymous reports. However, if no contact information is provided, we may be unable to request additional information or provide updates regarding the report.
When conducting security research involving Whale TV products or services, researchers should:
Researchers should not:
If you unintentionally access personal data, customer data or other sensitive information, please stop testing, do not copy or further access the information, and notify Whale TV as soon as reasonably possible.
Where practical, researchers should use test, demonstration or non-production environments and avoid testing products that are actively used in safety-critical, operational or customer environments.
Whale TV will review vulnerability reports and, where appropriate:
Where contact information is available, Whale TV aims to acknowledge receipt within seven business days of receiving a report, complete an initial triage within ten business days of receipt, and provide a status update at least every ten business days while the case remains open. These targets do not guarantee that validation, remediation, public disclosure, or resolution will be completed within those periods. The timing of further actions may vary depending on the nature, severity, and complexity of the reported issue.
A submitted report does not by itself mean that Whale TV has confirmed the existence or severity of a vulnerability.
Where a reported issue involves a third-party product, service or component, Whale TV may coordinate with the relevant third party as appropriate.
Whale TV supports coordinated vulnerability disclosure.
We ask researchers to contact Whale TV before publicly disclosing detailed information about a vulnerability, where reasonably possible, so that we can work together on appropriate timing and content of the disclosure.
The timing of public disclosure will be considered on a case-by-case basis, taking into account factors such as the availability of remediation or mitigation measures, the potential impact on users, and whether exploitation is occurring or suspected.
Whale TV may delay public disclosure where necessary to protect users or comply with applicable legal or regulatory requirements.
Whale TV will handle vulnerability reports and related information in accordance with applicable security, privacy and information-handling requirements.
Researchers should also take reasonable steps to protect confidential vulnerability information and avoid public disclosure that could enable exploitation before appropriate protective measures are available.
Whale TV may update this Policy from time to time to reflect changes in our products, security processes, regulatory requirements or vulnerability disclosure practices.
The current version of this Policy will be made available on this page.