Report a Security Issue
Responsible Disclosure
If you have found a vulnerability in a Hacking.cv service, tell us privately. We acknowledge reports within two business days and work with you on a remediation timeline.
Our policy
- • Report privately and give us reasonable time to fix the issue before publishing.
- • Test only against your own accounts and only in ways that avoid harm.
- • Do not access, modify or exfiltrate data belonging to other people.
- • No denial-of-service, spam, social engineering or physical attacks.
- • Good-faith research within these rules will not be met with legal action from us.
Never include secrets in a report
Do not send passwords, private keys, authentication tokens, session cookies or stolen credentials. We will not accept them, and we do not want them.
Security contact
security@hacking.cv
Also published at /.well-known/security.txt in line with RFC 9116.