If you have found a security problem in anything TicketWave HQ Ltd runs, we would rather hear it from you than from someone else. There is no bounty programme; there is a person who will read it and act.
The canonical version of this policy is ticketwavehq.com/security. This file says the same thing, so that a repository's Security tab and the website cannot disagree.
Email security@ticketwavehq.com with enough detail to reproduce the issue. Please do not report it through GitHub issues, pull requests or social media.
We acknowledge within two working days and aim to give a substantive response within seven.
Please give us a reasonable window to fix it before publishing, do not access or modify data that is not yours, and do not run tests that degrade the service for anyone else. We will not pursue anyone who reports in good faith under those terms.
- Findings from social engineering, physical attack, or denial of service.
- Reports against third-party services we use. Send those to the vendor, who can actually fix them.
- Theoretical issues with no demonstrated security impact.
- Best-practice notes, such as a missing header, with no route to exploitation.
Last updated 2026-10-07 · TicketWave HQ Ltd · Companies House 17143167 · England & Wales