Which route, account, or provider is affected?
Preparing the governed record.
Bookwiser is loading the requested public or applicant surface without changing its authority state.
Preparing the governed record.
Bookwiser is loading the requested public or applicant surface without changing its authority state.

Bookwiser distinguishes vulnerabilities, suspicious access, privacy exposure, data loss, abuse, and service incidents from ordinary product feedback. A report should identify the affected surface and observable evidence without accessing, changing, downloading, or disclosing more data than necessary.
These questions connect the public notice to real work, real responsibilities, and a clear next step instead of leaving it as abstract policy language.
Which route, account, or provider is affected?
What behaviour was observed?
When did it occur?
What minimal evidence supports the report?
The register explains what Bookwiser manages, what requires another person or provider, and which decisions remain outside this process.
Do not exploit beyond the minimum required to describe the issue.
Use authenticated support when the account remains available.
Avoid copying or redistributing exposed content.
Preserve message and route evidence without engaging further.
This is the expected path through Bookwiser. Actual service, account, provider, privacy, and legal obligations continue to follow the agreements and policies accepted for that relationship.
Stop testing, avoid further access, preserve minimal evidence, and use the security contact route.
Security classifies impact, affected surface, data, provider, exploitability, and immediate containment needs.
Access, provider, deployment, logging, notification, and evidence paths are reviewed by authorized people.
Resolution, communication, residual risk, follow-up controls, and disclosure decisions are retained.
These are Bookwiser's public commitments. Signed agreements, qualified professional opinions, and customer-specific deployment reviews add the terms required for each actual relationship.
Reports that follow the published safe-testing boundaries are handled as security work, not general feedback.
The reporter should not collect, retain, or disclose unrelated records to prove a concern.
Disclosure timing depends on containment, legal, privacy, provider, customer, and safety obligations.
The current procedure does not offer or imply a reward program.
For your protection, do not send passwords, credentials, tax identifiers, unredacted legal files, private customer records, or complete banking documents through a public contact path.