Legal
Vulnerability Disclosure Policy
Last updated: 22 September 2026
Bach.ai — operated by Wittelsbach Private Limited (“Wittelsbach”, “we”, “our”, “us”) — connects to advertising and e-commerce accounts on our customers’ behalf, so the security of this service is not an abstract concern. If you have found a vulnerability, we want to hear about it, and this page tells you exactly how to tell us and what you can expect from us in return. Our machine-readable security contact is published at /.well-known/security.txt (RFC 9116), and this page is the policy that file points to.
1. How to report
Email info@wittelsbach.ai with “Security” in the subject line. This is a monitored mailbox and the same address published in our security.txt. Please report privately by email rather than through our public contact form, social channels or a public issue tracker.
We do not publish a PGP key today, so please do not encrypt your first message to us. If your report contains material you are not willing to send in plain email, say so in the message and we will arrange a secure channel before you send the details.
2. What to include
A report we can reproduce is a report we can fix. Where you can, please give us:
- The exact URL, endpoint or page, and the host it is on (
www.wittelsbach.aiorapp.wittelsbach.ai). - The vulnerability class as you would describe it, and the impact you believe it has — what an attacker could actually read, change or do.
- Step-by-step reproduction instructions, and a minimal proof of concept if you have one. Screenshots, a request/response pair or a short video all help.
- The account or identifier you tested with, the approximate date and time (with timezone), and the source IP address you tested from, so we can separate your traffic from real attack traffic in our logs.
- Whether you accessed, downloaded or modified any data that was not yours — and if so, exactly what. Telling us is not held against you; not telling us makes it impossible for us to meet our obligations to the affected customer.
- How you would like to be credited, if you would like to be credited at all.
3. What you can expect from us
- Acknowledgement. We aim to acknowledge a security report within five business days — the same goal we publish for accessibility reports to this mailbox. This is a target we hold ourselves to, not a contractual guarantee or a support SLA.
- An honest assessment. We will tell you whether we could reproduce the issue and how we have rated it. If we decide not to fix something, we will say so and explain why, rather than leaving the report unanswered.
- Progress, not silence. Where a fix takes time, we will keep you updated as it moves, and let you know when it has shipped.
- Credit if you want it. We are happy to credit researchers publicly by the name or handle you choose, once the issue is fixed. Equally, we are happy to keep your report anonymous.
- We will tell affected customers. Where a vulnerability has exposed customer data, our duty is to those customers, and we will notify them as our Privacy Policy and applicable law require.
We do not operate a bug bounty. There is no monetary reward, and we would rather say that plainly here than have you discover it after doing the work.
4. Scope
The following are in scope for this policy:
www.wittelsbach.ai— this marketing site, including/.well-known/, our sitemaps and our public lead and advisory booking endpoints.app.wittelsbach.ai— the Bach.ai product, its API, its authentication and session handling, and its tenancy boundaries between customer accounts.
We are most interested in issues that let one customer reach another customer’s data, that let anyone act on a connected advertising account without the required approval, that expose or leak a connected-account access token, that break authentication or session handling, or that allow code execution on our infrastructure.
5. Out of scope
The following are outside this policy. Reports limited to these will usually be closed without a fix, and testing that involves them is not covered by section 7.
- Denial of service, volumetric and stress testing of any kind — load testing, traffic floods, resource-exhaustion attacks, or anything that degrades the service for other people.
- Social engineering of our staff, contractors, customers or suppliers, including phishing, pretexting, vishing and support-desk manipulation.
- Physical attacks against our offices, hardware or people.
- Testing against data or accounts that are not yours. Use your own account and your own connected ad account. Reaching into another customer’s data to “prove” an issue is not in-scope research — demonstrate the boundary failure and stop.
- Automated scanner output with no demonstrated impact. A tool’s report, pasted without a working proof of concept, is not a vulnerability report. Please do not run high-volume scanners against our hosts.
- Third-party platforms. Issues in Meta, Google Ads, Shopify, Razorpay, Calendly, or any other service we integrate with belong to that provider’s own disclosure programme, not to us. Report them there.
- Findings with no practical exploit — missing security headers, cookie flags on non-sensitive cookies, TLS configuration or cipher preferences, software version banners, clickjacking on pages with no sensitive action, self-XSS, and mail-configuration reports (SPF, DKIM, DMARC) without a demonstrated working spoof.
- Issues that require a compromised, rooted or man-in-the-middled device, a hostile browser extension, or an end-of-life browser.
- Rate limiting on public forms where the only outcome is unwanted volume, and content-spoofing or text-injection issues with no security consequence.
6. Rules of engagement
Research covered by this policy is research that keeps other people safe while it happens:
- Test only with accounts you own or have written permission to test. Our free plan lets you create one without payment.
- Stop as soon as you have confirmed a vulnerability. Do not continue to access data to measure how far it goes.
- Do not access, copy, exfiltrate, alter or delete data that is not yours, and do not retain any such data you encounter — tell us instead, and delete it when we ask.
- Do not degrade, interrupt or take down the service, and do not modify or take down other people’s ad campaigns, budgets or creative.
- Do not use a vulnerability to pivot deeper into our infrastructure, to install a backdoor or persistence, or to maintain access after reporting.
- Keep the issue confidential until we have fixed it. We ask for 90 days from your report before public disclosure, and we will work with you if you want to publish sooner or if the fix needs longer. Tell us your intended timeline and we will tell you ours.
- Comply with the law that applies to you and to us. Nothing in this policy authorises anything unlawful.
7. Good-faith research and safe harbour
We want researchers to report to us without fearing what we will do next. So we commit, for research we consider to have been carried out in good faith and within this policy:
- We will not initiate, encourage or support a legal complaint or claim against you for that research, and we will not ask a regulator or law-enforcement body to pursue you for it.
- We will not treat it as a breach of our Terms & Conditions, and in particular not as a breach of the acceptable-use rule against interfering with the Service. We will not suspend or terminate your account for it.
- If a third party brings a claim against you over research that met this policy, we will make it known, publicly if you need us to, that your activity was conducted in accordance with a policy we published and invited you to follow.
- If we believe you have stepped outside this policy, we will tell you what we think went wrong and give you a chance to answer before we take any other step.
Please read these as commitments rather than as legal immunity, because that is what they honestly are. We cannot waive the rights of our customers, of the advertising and payment platforms we connect to, or of any other third party, and we cannot grant you an exemption from the computer-misuse, data-protection or other laws of your country or ours. If you are unsure whether something you are planning is covered, ask us first at info@wittelsbach.ai — we would much rather answer that question in advance.
8. If you are a customer with an urgent security problem
This page is for vulnerability research. If your own Bach.ai account or a connected advertising account has been compromised, do not wait on a research timeline: email info@wittelsbach.ai and say that it is urgent, or use our contact page. You can disconnect a connected account and revoke our access at any time from your settings.
9. Changes to this policy
We may update this policy as our service and our security practice change. The current version is always on this page with a new “Last updated” date, and it is the version linked from /.well-known/security.txt.
10. Contact
Security reports and questions about this policy:
Wittelsbach Private Limited
Banjara Hills, Road No. 12, Hyderabad – 500034, Telangana, India
Email: info@wittelsbach.ai
Website: https://www.wittelsbach.ai