Solutions Pricing Features Why Webilly Customers
IT Book a demo

Report a vulnerability

Coordinated vulnerability disclosure policy of Wenetwork srl for the Webilly product.
Last updated: 5 September 2026

If you have found a security issue in Webilly, write to us. A person will answer, and your report stays confidential.

How to report

security@webilly.it

In English or Italian. As much of this as you can give us:

  • what you found, and why it is a problem;
  • how to reproduce it — roughly is fine: we would rather have an approximate description today than a perfect one in three weeks;
  • the Webilly version (bottom of the application sidebar) and how it is installed, if you know;
  • how you want to be credited when we publish the fix, or whether you would rather not be.

A working exploit is not required. If you have one, do send it: it stays between us.

What we ask of you

  • Report to us before anyone else, and give us time to fix it.
  • Do not access data that is not yours, do not modify it, do not delete it. If you saw any while verifying, tell us: we need to know who to notify.
  • No attacks on service availability, no social engineering against our customers or our staff.
  • If the issue is with a customer's installation rather than the product, tell them. If you cannot tell the difference, write to us and we will route it.

What we do

within 3 working days we confirm we received your report
within 10 working days we tell you whether we reproduced it, how we rate it and what we intend to do
throughout we keep you posted at every step that matters
on the fix we publish a security advisory, ship the patch to installations and credit you, if you want

We do not pay rewards: there is no bug bounty programme. Public credit in the advisory, yes, if you want it.

What is in scope

The Webilly product: the back-office application, the customer area, the field-technician app, the APIs, the update mechanisms and the installation procedure.

Out of scope — but write to us anyway if in doubt, we will route it:

  • the configuration of an individual customer installation (for example a reverse proxy that does not enforce TLS): we forward it to whoever runs it;
  • third-party components we integrate (FreeRADIUS, MySQL, Gotenberg, Stripe, PayPal, the Italian e-invoicing exchange): we report them upstream and assess our exposure;
  • this website, which is not the product.

Security advisories

Fixed vulnerabilities are published — what they were, who was exposed, how severe, what to do — together with the version that fixes them. Whoever runs an installation is also notified directly.

Security fixes are free of charge and are distributed to all supported installations, regardless of the contract in place.

Regulatory basis

This policy fulfils the coordinated vulnerability disclosure obligations of Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I Part II.

For actively exploited vulnerabilities and severe incidents we are required to notify the competent CSIRT and ENISA within short deadlines, and to inform affected installations. Reporting to us does not expose you: reports are never attributed to the sender without their consent.

The same information is available in machine-readable form at /.well-known/security.txt (RFC 9116).

← Back to home

Wenetwork srl

Via Andrea Ferrara — Tursi (MT)

VAT 01326970777

info@webilly.it

Follow us on

  • LinkedIn
  • YouTube
  • X / Twitter

© Wenetwork srl. All rights reserved.

Cookie & Privacy Policy Security