Security

Responsible Disclosure Policy

We appreciate security researchers who help keep OpenHack and our users safe.

Scope

This policy applies to vulnerabilities in:

  • The OpenHack web application (openhack.com)
  • The OpenHack API
  • OpenHack's public-facing infrastructure

How to Report

Please send vulnerability reports to security@openhack.com with:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any supporting evidence (screenshots, proof of concept)

What to Expect

  • Acknowledgment: We will acknowledge receipt of your report within 2 business days.
  • Assessment: We will investigate and validate the reported vulnerability within 5 business days.
  • Resolution: We aim to resolve confirmed vulnerabilities within 30 days, depending on severity and complexity.
  • Communication: We will keep you informed of our progress throughout the process.

Safe Harbor

We consider security research conducted consistent with this policy to be:

  • Authorized concerning any applicable anti-hacking laws
  • Authorized concerning any relevant anti-circumvention laws
  • Exempt from restrictions in our Terms of Service that would interfere with conducting security research

We will not pursue civil action or initiate a complaint to law enforcement for accidental, good-faith violations of this policy.

Guidelines

We ask that you:

  • Do not access, modify, or delete data belonging to other users
  • Do not degrade the performance or availability of our services
  • Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it
  • Act in good faith to avoid privacy violations and disruptions to our users

Out of Scope

The following are generally not considered vulnerabilities under this policy:

  • Social engineering attacks against our employees
  • Physical security issues
  • Denial of service attacks
  • Spam or social engineering via email
  • Issues in third-party applications or services not under our control

Recognition

We appreciate responsible disclosure and are happy to acknowledge researchers who report valid vulnerabilities, with their permission.

Contact

Email: security@openhack.com