SECURITY
Responsible disclosure and acknowledgements
Last updated: 24.08.2026
Reporting a vulnerability
If you believe you have found a security issue in Wizia AI — the platform, the try-on widget, or any wizia.ai service — please email hello@wizia.ai. This mailbox is monitored every day, and security reports are passed to the engineers who own the affected code the same working day.
Please include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. We will confirm receipt and keep you informed of what we find and fix.
A machine-readable version of this policy is published at /.well-known/security.txt.
What we ask
We welcome good-faith security research. When testing, please do not access, modify or delete data that is not your own beyond the minimum needed to demonstrate the issue; do not degrade the service for our merchants and their shoppers; do not use social engineering against our team or customers; and give us reasonable time to fix an issue before disclosing it publicly. We will not pursue legal action over research conducted in line with these principles.
What we offer
Wizia AI does not run a paid bug bounty programme. What we offer instead is public credit: researchers whose reports lead to a fix are listed on this page, with their consent and under the name they choose. Every report is reviewed and fixed on the same footing whether or not the reporter wishes to be named.
Acknowledgements
Our thanks to the researchers who have reported issues responsibly:
- August 2026 — missing MTA-STS policy (email transport hardening), reported responsibly, fixed and independently verified. Reported by Muhammad Usama.