Version 1.0 - effective 28 August 2026

Vulnerability Disclosure Policy

Report suspected vulnerabilities to sander@waldo.studio. Stop testing immediately if you access personal, health, financial, credential, or other non-public data.

1. Introduction

Waldo Studio BV welcomes good-faith security research that helps protect Century and its users. This policy explains which assets may be tested, how to avoid harm, what to include in a report, and the safe-harbor conditions under which Waldo Studio BV will not pursue legal action.

2. In-scope assets

https://joincentury.app and first-party API paths served from that domain.

The legacy centuryai.app hostname only where it redirects to or serves a first-party Century endpoint.

Century's publicly released iOS application with bundle identifier com.waldostudiobv.century.

Century's publicly released Android application with package identifier com.waldostudiobv.century.

Only assets explicitly listed above are authorized. Third-party services such as Google, Supabase, Hetzner, Disco, Mapbox, PostHog, RevenueCat, Apple, Garmin, domain providers, and their infrastructure are not in scope and must be reported to the applicable provider under its policy.

3. Research guidelines

Use accounts and data you own or have explicit permission to test. Do not access another user's account or data. Use the minimum interaction necessary to demonstrate a vulnerability. Do not establish persistence, pivot to another system, exfiltrate data, or alter production records beyond your own test data.

Stop immediately and notify us if you encounter personal data, health data, credentials, tokens, secrets, private source code, or financial information. Do not retain or disclose it.

Avoid privacy violations, service degradation, excessive automated requests, and actions that could affect users or production availability.

Do not publicly disclose a vulnerability until Waldo Studio BV has had a reasonable opportunity to investigate and remediate it and you have coordinated disclosure timing with us.

Do not submit large volumes of low-quality, duplicate, purely theoretical, or scanner-only reports without clear security impact.

4. Prohibited testing

Do not perform denial-of-service, distributed denial-of-service, traffic flooding, resource exhaustion, or stress testing.

Do not perform social engineering, phishing, vishing, impersonation, or testing of employees, contractors, customers, or support channels.

Do not perform physical-security testing, malware or destructive-payload testing, persistence, credential stuffing, password spraying, brute-force attacks, mass account creation, spam, payment fraud, or interference with app-store or provider systems.

Do not test third-party infrastructure or access, modify, delete, download, or publish data that is not your own.

5. Reporting a vulnerability

Send reports in English to sander@waldo.studio. Include a clear description and potential impact; the affected URL, app version, API path, or component; reproduction steps using only your own test data; sanitized screenshots, logs, or a minimal proof of concept; required exploitation conditions; suggested remediation; and your preferred name and contact details, or state that the report is anonymous.

6. Our response commitment

We aim to acknowledge a complete report within three business days. We will investigate, validate severity, and keep the reporter reasonably informed when contact details are provided.

Remediation timing depends on severity, complexity, user impact, provider dependencies, and safe release requirements. We will coordinate public disclosure when appropriate. We do not currently operate a monetary bug-bounty program, and no reward is promised.

7. Safe harbor

When research is conducted in good faith and in accordance with this policy, Waldo Studio BV considers it authorized and will not initiate legal action solely for that research. If a third party initiates legal action, we may state that the research was conducted under this policy. This safe harbor does not authorize violations of law, third-party rights, privacy, contractual duties, or activity outside the listed scope.

8. Privacy and disclosure

Reporters must keep all non-public information confidential and securely delete it when asked or when no longer needed for coordinated remediation. Waldo Studio BV may share a report with affected service providers, professional advisers, insurers, regulators, or law enforcement when necessary to investigate, remediate, or meet legal obligations.

9. Questions and policy updates

If you are uncertain whether an activity is permitted, contact sander@waldo.studio before testing. Waldo Studio BV may update this policy as Century's systems and risk profile evolve. The version and effective date above identify the applicable revision. Next review: 28 August 2027.

Frequently asked questions

Your Apple Watch captures the same core biometrics Whoop relies on—heart rate variability, resting heart rate, sleep stages, and activity strain. Century decodes that data with pro-level coaching so you get the clarity and motivation Whoop is known for, without buying another band.

No extra hardware required. Century unlocks the sensors already on your Apple Watch or compatible wearable so you can ditch duplicate straps.

Century offers flexible plans—including a lifetime option—so you can pay once and keep access forever.

Century works with Apple Watch, Apple Health, Android Health Connect, Garmin Connect, and Fitbit through Google Health.

Vulnerability Disclosure Policy - Century