Security
Responsible Disclosure Policy.
We take the security of our systems seriously. If you discover a security vulnerability in hackproofhacks.com or any of our systems, we want to hear from you.
Our commitments to you.
- Acknowledge your report within 48 hours
- Provide regular status updates on the investigation
- Not pursue legal action against researchers who follow this policy
- Credit you publicly (if you wish) once the vulnerability is resolved
- Work with you to understand and resolve the issue
What we ask of you.
- — Give us reasonable time (90 days) to address the issue before public disclosure
- — Do not access, modify, or delete data that does not belong to you
- — Do not perform DoS or DDoS attacks
- — Do not use automated scanners in a way that disrupts service availability
- — Do not social-engineer our staff or users
In scope.
- hackproofhacks.com and all subdomains
- Any API endpoints operated by HackproofHacks
Out of scope.
- Third-party services and software not under our direct control
- Denial of service attacks
- Social engineering attacks
- Physical security
- Issues already reported by another researcher
How to report.
Send your report to connect@hackproofhacks.com with the subject line [Vulnerability Report]. Include:
- • Description of the vulnerability and its potential impact
- • Steps to reproduce the issue
- • Screenshots or proof-of-concept code (where applicable)
- • Your name and contact details (or request for anonymity)