Legal & Safety

Responsible Disclosure Policy

How to report a vulnerability to us, and what we commit to in return.

← All policies

Report vulnerabilities privately to security@hacking.cv. We acknowledge within two business days, agree a remediation timeline, and credit reporters who wish to be named. Good-faith research within our published rules will not be met with legal action from us.

Never include passwords, session tokens, API keys or third-party data in a report. Describe the issue and how to reproduce it instead.