Last updated:
Found a genuine vulnerability in our systems? We want to hear about it, and we're grateful when someone takes the time to report it properly rather than exploit it. Report it to us directly first, and we'll take it from there.
Email [email protected] rather than a public issue tracker or social media, so the details stay between us while we look into it.
Your report is most useful to us when it includes:
The more detail you give us, the faster we can confirm and fix it. If something's unclear, we'll just ask.
We'll acknowledge every legitimate report within 3 business days, then investigate, confirm, and fix it based on how serious it is.
We ask that you hold off on public disclosure until we've had a genuine chance to fix the issue. Coordinated disclosure protects your credit and our users at the same time, and we'll keep you updated on progress.
Testing enough to demonstrate a vulnerability exists is fine. A few things we ask you to avoid along the way:
Stick to that and act in good faith, and we will not pursue legal action against you for the research itself.
This policy covers:
It does not cover third-party systems we don't control, or client systems we no longer support.
We don't run a paid bug bounty programme, and reporting a vulnerability doesn't entitle you to payment. We do appreciate good work and may credit or thank exceptional reports at our discretion.
If a report includes something sensitive, say so in your first email and ask for an encrypted channel. We'll set one up before you send anything further.
Security Team
[email protected]
Hiddenite Limited