Findings about services Wasit tests

When Wasit finds a conformance defect in somebody else's service:

  • The operator is told privately first, with enough detail to reproduce it.
  • A reasonable window is given to respond before anything is published.
  • Aggregate results may be published — how many services were tested and what classes of defect appeared — but no individual service is named without its operator's written permission.
  • A defect that is exploitable, rather than merely non-conformant, is treated as a vulnerability disclosure rather than a test result, and is not published on a timetable of ours.

A FAIL from Wasit is a statement about a specific check against a specific target at a specific moment. It is not a security assessment. See design/scope-boundary.md for what a passing result does and does not mean.