Legal & trust
Security and disclosure
How Chargewise protects customer information and receives responsible vulnerability reports.
Last updated 13 July 2026
Core controls
Chargewise uses encrypted transport, HTTP-only sessions, role-based access, same-origin write protection, rate limits, private document storage, one-time claim capabilities, human QA gates, structured audit events, dependency scanning, production monitoring and tested backup-and-restore procedures.
Responsible disclosure
Send a clear report to security@getchargewise.com. Include the affected URL, reproduction steps, impact and any supporting request or response details. Do not access other customers' data, persist access, use destructive testing, run denial-of-service tests or publish a vulnerability before we have had a reasonable opportunity to investigate.
Our response
We aim to acknowledge a security report within two business days, validate and prioritise it, keep the reporter informed and remediate according to severity. Good-faith research that follows this policy will not be treated as hostile activity.