This policy is the org-wide default. Individual repos may provide their own
SECURITY.md with project-specific detail; treat that as the source of truth
for anything project-specific.
Do not open a public issue.
To report a vulnerability in one of our open source projects, please use GitHub's private vulnerability reporting on the affected repository:
Securitytab →Report a vulnerability
This creates a private security advisory that only the project maintainers can see.
If you've found a vulnerability in the Wealthsimple platform itself (e.g.
wealthsimple.com, our mobile apps, or our production APIs) — not in one of our
open source libraries — please email opensource@wealthsimple.com and we'll
route it appropriately.
These projects are maintained on a best-effort basis, so response times vary. We aim to acknowledge reports promptly and prioritize by severity.
For non-security defects, please file a regular bug report using the project's issue template.
For general questions and support, see SUPPORT.md.