Security

Security Disclosure

Last updated:

Found a genuine vulnerability in our systems? We want to hear about it, and we're grateful when someone takes the time to report it properly rather than exploit it. Report it to us directly first, and we'll take it from there.

1. How to report

Email [email protected] rather than a public issue tracker or social media, so the details stay between us while we look into it.

Your report is most useful to us when it includes:

  • The affected URL, endpoint, application, or system
  • What the vulnerability is and why it matters
  • Steps to reproduce it
  • Supporting evidence: screenshots or logs (please don't send live exploit code or scripts, describe the technique in words instead)
  • A way to reach you for follow-up

The more detail you give us, the faster we can confirm and fix it. If something's unclear, we'll just ask.

2. What we commit to

We'll acknowledge every legitimate report within 3 business days, then investigate, confirm, and fix it based on how serious it is.

We ask that you hold off on public disclosure until we've had a genuine chance to fix the issue. Coordinated disclosure protects your credit and our users at the same time, and we'll keep you updated on progress.

3. Good faith research

Testing enough to demonstrate a vulnerability exists is fine. A few things we ask you to avoid along the way:

  • Accessing, downloading, or altering data that isn't yours
  • Denial of service, brute force, spam, or destructive testing
  • Disrupting a live client environment
  • Phishing, social engineering, or physical access to get in
  • Disclosing the issue publicly before it's fixed

Stick to that and act in good faith, and we will not pursue legal action against you for the research itself.

4. What's in scope

This policy covers:

  • hiddenite.uk and the infrastructure behind it
  • Systems we host and operate directly
  • Client systems we actively manage

It does not cover third-party systems we don't control, or client systems we no longer support.

5. No bug bounty

We don't run a paid bug bounty programme, and reporting a vulnerability doesn't entitle you to payment. We do appreciate good work and may credit or thank exceptional reports at our discretion.

6. Sending sensitive details

If a report includes something sensitive, say so in your first email and ask for an encrypted channel. We'll set one up before you send anything further.

7. Contact

Security Team
[email protected]
Hiddenite Limited