Responsible Disclosure

    Last updated: 30 April 2026

    Report a vulnerability

    Email security@wheniamgone.co.za with the subject line "Security report". We acknowledge reports within two business days and aim to provide a substantive update within ten business days.

    Our commitment

    When I Am Gone (Pty) Ltd ("WIAG") protects highly sensitive personal and estate information for South African families and practitioners. We rely on the security research community to help us find and fix issues that could put that data at risk. If you believe you have found a vulnerability, please tell us in line with this policy and we will work with you in good faith.

    Safe harbour

    We will not initiate legal action against researchers who:

    • Make a good-faith effort to comply with this policy and avoid privacy violations, data destruction, and service interruption.
    • Report the issue to us promptly and give us reasonable time to remediate before public disclosure.
    • Do not exploit a vulnerability beyond the minimum needed to demonstrate it.
    • Do not access, modify, exfiltrate, or retain data belonging to other users.

    If a third party brings legal action against you for activities that complied with this policy, we will make it known that your actions were authorised.

    In scope

    • wheniamgone.co.za and its subdomains.
    • WIAG-operated APIs, web applications, and authentication flows.
    • Vulnerabilities in our handling of vault data, audit logs, encryption keys, payments, and access tokens.

    Out of scope

    • Findings against third-party services we depend on (Paystack, Resend, Neon, and other vendors). Please report those directly to the relevant vendor.
    • Theoretical issues without a working proof of concept, missing best-practice headers without a demonstrable impact, rate-limit findings, and findings from automated scanners without exploitation analysis.
    • Social engineering, physical attacks, denial-of-service, and attacks requiring privileged access to a victim's device or account.
    • Content spoofing or text injection without an attached exploit chain.

    What to include

    • A clear description of the vulnerability and its impact.
    • Steps to reproduce, including any required accounts or payloads.
    • The URLs, parameters, and request/response samples involved.
    • Your contact details and (optionally) a name or handle for credit.

    What happens next

    1. We acknowledge your report within two business days.
    2. Our Information Officer triages the report and confirms the finding, severity, and remediation timeline within ten business days.
    3. We keep you updated through remediation and notify you when a fix is deployed.
    4. With your permission, we credit you publicly once the issue is resolved.

    Bounties

    WIAG does not currently run a paid bug bounty programme. We publicly thank researchers who follow this policy and may offer goodwill rewards at our discretion.

    Information Officer

    Natalie Macdonald Spence, security@wheniamgone.co.za

    Machine-readable contact details are also published at /.well-known/security.txt.

    PGP key

    Key not yet published

    A PGP public key for security@wheniamgone.co.za will be published here once it is generated and uploaded to a public key server. In the meantime, send your report unencrypted to the address above. If you need to share sensitive proof-of-concept material, contact us first and we will arrange a secure channel.

    Hall of thanks

    Researchers who responsibly disclose vulnerabilities in accordance with this policy will be listed here with their permission, once the relevant issue has been resolved. We are grateful to everyone who takes the time to help us keep South African families' estate information safe.

    No disclosures have been received yet.

    When I Am Gone is a life-file and estate-readiness platform. It is not a law firm, financial adviser, estate administrator, executor service, probate service or insurer. The platform stores information you supply and helps you keep it organised; it does not provide legal, tax or financial advice.

    When I Am Gone (Pty) Ltd ("When I Am Gone") is a registered Financial Services Provider (FSP No: 55699) providing secure digital information storage and estate-readiness tools. When I Am Gone is not a law firm or estate planning professional. For personalised legal, tax or estate planning advice, consult a qualified attorney or fiduciary practitioner. Executors and beneficiaries are responsible for verifying information and obtaining professional advice before acting.

    Will documents created using When I Am Gone must be printed, reviewed, and signed in the presence of two competent witnesses as required by the Wills Act 7 of 1953. Electronic wills are not valid under South African law. When I Am Gone does not verify will validity, witness competency, or guarantee executor or Master of the High Court acceptance.

    When I Am Gone (Pty) Ltd is responsible for its account and service administration. Private vault content uses browser encryption, while metadata and some requested services use readable or server-encrypted records. Our Privacy Policy explains purposes, providers, international transfers, retention and your rights. Account closure does not by itself confirm complete deletion. Lawfully retained records remain subject to appropriate access and use restrictions.

    You have the right to access, correct, delete, or object to processing of your personal information. Contact our Information Officer at support@wheniamgone.co.za for data subject requests. POPIA security-compromise notifications must be made as soon as reasonably possible, subject to the specific legal exceptions and permitted delays. See our Privacy Policy for full details.

    © 2026 When I Am Gone (Pty) Ltd. All rights reserved. Registered in South Africa.

    When I Am Gone is a registered Financial Services Provider | FSP No: 55699 | Regulated by the FSCA

    Administrative vault services are non-FAIS. Insurance services, where live, are financial services and are provided under the relevant authorisation, disclosures and product-provider terms. The will wizard and estate vault are software tools, not FAIS products. Insurance cover products are not yet on sale. When insurance products are offered, any remuneration will be regulated under FAIS and disclosed before any transaction. CPA and ECTA cooling-off rights apply where the transaction qualifies. The FSP licence is held by When I Am Gone alone and is never re-presented under a partner brand.

    When I Am Gone