Findings about services Wasit tests
When Wasit finds a conformance defect in somebody else's service:
- The operator is told privately first, with enough detail to reproduce it.
- A reasonable window is given to respond before anything is published.
- Aggregate results may be published — how many services were tested and what classes of defect appeared — but no individual service is named without its operator's written permission.
- A defect that is exploitable, rather than merely non-conformant, is treated as a vulnerability disclosure rather than a test result, and is not published on a timetable of ours.
A FAIL from Wasit is a statement about a specific check against a specific target at a specific moment. It is not a security assessment. See design/scope-boundary.md for what a passing result does and does not mean.
