Vulnerability Disclosure Policy

Effective August 16, 2026 · Last updated August 16, 2026

Security is core to what we do. We welcome reports from security researchers and will work with you in good faith to verify and fix issues. This policy explains what’s in scope, how to report, what we ask of you, and our safe-harbor commitment.

1. How to report

Email privacy@hukproof.com with a clear description of the issue, the steps to reproduce it, its potential impact, and any proof-of-concept. If the report is sensitive, say so and we’ll arrange a secure channel. Please give us a reasonable time to remediate before any public disclosure.

2. Scope

In scope: our public websites, the HukProof application, and our API.

Out of scope (please do not test these):

  • Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion testing.
  • Social engineering, phishing, or physical attacks against HukProof staff, users, or facilities.
  • Attacks against third-party services we use (report those to the relevant provider).
  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Best-practice suggestions with no security impact (e.g. missing headers with no exploit).

3. Rules of engagement

To keep testing safe and lawful, you agree to:

  • Only access, modify, or delete your own test data — never another customer’s or user’s data.
  • Stop and report as soon as you encounter personal data; do not access, download, or retain it beyond the minimum needed to demonstrate the issue.
  • Not degrade, disrupt, or exfiltrate data from our services.
  • Not use the platform to send simulations to anyone outside a test organization you control (see our Acceptable Use Policy).
  • Comply with all applicable laws.

4. Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity conducted in accordance with this policy, we will make our authorization known. This safe harbor does not apply to activity that is malicious, that violates the law, or that goes beyond this policy.

5. Our commitment

  • We will acknowledge your report promptly and keep you reasonably informed of progress.
  • We will investigate and remediate valid issues on a timeline appropriate to severity.
  • We do not currently run a paid bug-bounty program, but we are glad to credit researchers who wish to be acknowledged.

6. Coordinated disclosure

We ask that you keep vulnerability details confidential until we confirm a fix or mutually agree on a disclosure timeline. We aim to resolve validated reports promptly and to coordinate any public write-up with you.

Last updated August 16, 2026 · privacy@hukproof.com