Tailwind Reviews Vulnerability Disclosure Policy

legal.version: 1.1legal.effectiveDate: 2026-09-24

Tailwind Reviews LLC is committed to the security of our customers and their data. We welcome reports from security researchers and encourage responsible disclosure.

1. Scope

This policy covers:

  • Tailwind Reviews websites (tailwind.reviews and its subdomains);
  • the Tailwind Reviews web application;
  • Tailwind Reviews APIs, including our MCP server, and backend services.

Not in scope:

  • third-party services and applications;
  • social engineering, phishing or spam;
  • physical security;
  • denial-of-service attacks.

2. How to report

E-mail support@tailwind.reviews with the subject "Security", including:

  • a description of the vulnerability;
  • steps to reproduce it;
  • its potential impact;
  • any suggestions for fixing it.

3. Our commitments

When you report a vulnerability, we will:

  • acknowledge your report promptly;
  • give you an estimated timeline for a fix;
  • tell you when it is fixed;
  • not take legal action against researchers who follow this policy in good faith.

4. What we ask of you

  • Give us reasonable time to fix the issue before disclosing it publicly.
  • Avoid privacy violations, data destruction and service disruption.
  • Do not access or change data that does not belong to you. If you reach such data by accident, stop and tell us.

With your permission, we may publicly thank you for your contribution.

Suscríbete a nuestro boletín

Enviamos materiales útiles una vez al mes, junto con información sobre descuentos y ofertas especiales. Sin spam diario

newsletter.subscribe.privacyNotice

¿Cómo cancelo mi suscripción al boletín?