HackproofHacks
Security

Responsible Disclosure Policy.

We take the security of our systems seriously. If you discover a security vulnerability in hackproofhacks.com or any of our systems, we want to hear from you.

Our commitments to you.

  • Acknowledge your report within 48 hours
  • Provide regular status updates on the investigation
  • Not pursue legal action against researchers who follow this policy
  • Credit you publicly (if you wish) once the vulnerability is resolved
  • Work with you to understand and resolve the issue

What we ask of you.

  • Give us reasonable time (90 days) to address the issue before public disclosure
  • Do not access, modify, or delete data that does not belong to you
  • Do not perform DoS or DDoS attacks
  • Do not use automated scanners in a way that disrupts service availability
  • Do not social-engineer our staff or users

In scope.

  • hackproofhacks.com and all subdomains
  • Any API endpoints operated by HackproofHacks

Out of scope.

  • Third-party services and software not under our direct control
  • Denial of service attacks
  • Social engineering attacks
  • Physical security
  • Issues already reported by another researcher

How to report.

Send your report to connect@hackproofhacks.com with the subject line [Vulnerability Report]. Include:

  • • Description of the vulnerability and its potential impact
  • • Steps to reproduce the issue
  • • Screenshots or proof-of-concept code (where applicable)
  • • Your name and contact details (or request for anonymity)
Send vulnerability report