NetSpot Vulnerability Disclosure Policy

Last updated: August 19, 2026

Etwok Inc. (“Etwok”), the developer of the NetSpot app, takes security seriously. We welcome reports from researchers and users who identify potential vulnerabilities in our products and services, and we’re committed to working with you to resolve them.

Scope

This policy covers:

  • The NetSpot applications (Windows, macOS, Android, iOS)
  • The NetSpot website (netspotapp.com) and our licensing/activation services

Note that NetSpot processes your WiFi survey, network, and location data locally on your device — that data is not sent to or stored on our servers.

How to report

Email onair@netspotapp.com with:

  • a description of the issue and where you found it,
  • steps to reproduce (proof-of-concept, logs, or screenshots help), and
  • the affected product, version, and platform.

Please report privately — don’t disclose the issue publicly until we’ve had a reasonable chance to discuss/confirm it with you and fix it.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. This authorization applies notwithstanding the use restrictions in our End-User License Agreement.

What we ask

  • Give us a reasonable time to investigate and remediate before any public disclosure.
  • Don’t access, modify, or delete data that isn’t yours, and don’t degrade or disrupt our services.
  • Don’t exploit the issue beyond what’s needed to demonstrate it, and stop if you encounter personal data.
  • Comply with all applicable laws.

What to expect from us

  • We’ll acknowledge your report within 3 business days.
  • We’ll keep you updated as we investigate and remediate.
  • We’ll credit you for your discovery if you’d like, once the issue is resolved.
  • We’ll gladly consider reasonable rewards to researchers who help keep NetSpot secure.

Out of scope

Reports limited to the following are generally not in scope: denial-of-service (DoS/DDoS), spam or social-engineering of our staff or users, and findings from automated scanners without a demonstrated, exploitable impact.

updated: August 19, 2026 author: alex
Have more questions? Submit a request.