generated: '2026-08-02' method: searched probe: true source: >- https://global.wyze.com/pages/security-report (full published policy text), https://www.wyze.com/pages/wyzes-vulnerability-disclosure, https://www.wyze.com/pages/security-report and https://bugcrowd.com/engagements/wyze policy: - https://www.wyze.com/pages/wyzes-vulnerability-disclosure - https://global.wyze.com/pages/security-report - https://bugcrowd.com/engagements/wyze contact: - security@wyze.com security_txt: none last_updated: 'January 2026' bug_bounty: platform: Bugcrowd url: https://bugcrowd.com/engagements/wyze name: Wyze Bug Bounty out_of_scope_intake: wyzevpd@submit.bugcrowd.com rating_taxonomy: Bugcrowd Vulnerability Rating Taxonomy (VRT) scope_note: >- Wyze states it welcomes security researchers to help identify vulnerabilities in its web app and API. process: steps: - id: reporting description: >- The Wyze Cybersecurity team becomes aware of a potential vulnerability; the reporter receives an acknowledgement and updates throughout handling. - id: evaluation description: >- The team confirms the vulnerability, assesses risk and impact, and assigns a processing priority. - id: solution description: >- A fix is developed with the product team; where a vulnerability is actively exploited a temporary containment may ship ahead of the full solution. - id: communication description: >- A security advisory is published for severe issues; less severe issues are communicated through other methods. slas: acknowledgement: within 48 hours (business days) status_updates: at least once every 7 days while under investigation or remediation resolution_target: approximately 3-4 weeks for confirmed vulnerabilities submission_guidance: - clear description of the issue - the affected product or service - steps to reproduce, if known - relevant screenshots, logs, or proof-of-concept information responsible_disclosure: >- Wyze asks that issues not be publicly disclosed until it has had a reasonable opportunity to investigate and address them, and commits to working in good faith with reporters. safe_harbor_note: >- Wyze states that reporting a security vulnerability will not affect product warranty or access to customer support. No formal legal safe-harbour clause is published on the disclosure page itself. suspicious_activity_intake: url: https://www.wyze.com/pages/security-report contact: security@wyze.com requested_details: - detailed description of the issue - products and versions affected - device MAC address (ID) - account email address - time of the issue - submitted Log ID from the mobile app evidence: - source: https://global.wyze.com/pages/security-report kind: disclosure-policy http_status: 200 keywords: [responsible disclosure, security@wyze.com, vulnerability, acknowledgement] - source: https://www.wyze.com/pages/wyzes-vulnerability-disclosure kind: disclosure-page http_status: 200 note: >- Shopify page rendered client-side with template suffix "bugcrowd" - it embeds the Bugcrowd program rather than serving static policy text. - source: https://bugcrowd.com/engagements/wyze kind: bug-bounty http_status: 200 - source: https://www.wyze.com/pages/security-trust kind: security-hub http_status: 200 x-evidence: fetched: '2026-08-02'