What we’re looking for in your report.
To triage faster, please include the following — anything you can. If you can’t, submit anyway and we’ll follow up.
- What you observed — the suspect URL / endpoint / message and what made it suspicious.
- Time of observation — UTC or your local timezone. Earliest and latest if it spans a window.
- Affected workspace — your tenant slug (e.g. {slug}.app.wendesk.com) and the user or asset involved.
- Reproduction steps — minimal repro if you can. Coordinated disclosure for vulnerabilities is welcomed; we ack within 24h, fix within 30 days.
- Active exploitation — if confirmed exploitation is in progress, page [email protected] directly with [ACTIVE] in the subject.
What counts as a security incident.
Potential unauthorised access to your tenant data, exfiltration or tampering.
Bug or misconfiguration that could lead to unauthorised access — coordinated disclosure welcomed.
Phishing impersonating Wendesk, abusive use of the platform, spam coming from a tenant workspace.
सक्रिय सुरक्षा उल्लंघन के लिए [email protected] पर सीधे ईमेल करें।
What we do after you submit.
- Acknowledge in 24h
Auto-routed to the on-call security team plus a named handler.
- Triage + contain
Severity classified, scope defined, customer-impacting actions taken first.
- Notify + remediate
72-hour DPDP / GDPR breach notice if confirmed; full RCA within 30 days.
What’s in scope for this form.
| Type | In scope (use this form) | Out of scope (use a different channel) |
|---|---|---|
| Security | Suspected unauthorised access · vulnerability disclosure · phishing impersonating Wendesk | Lost password → /forgot-password |
| Privacy | Suspected data breach affecting your tenant | General DSR rights → /dsr-request |
| Abuse | Spam · phishing · TOS-violating content from a Wendesk tenant | Marketplace product complaint → vendor’s storefront support |
| Compliance | Suspected breach of DPDP / GDPR / HIPAA obligations | General complaint → /grievance |