Security
Responsible Disclosure Policy
We appreciate security researchers who help keep OpenHack and our users safe.
Scope
This policy applies to vulnerabilities in:
- The OpenHack web application (openhack.com)
- The OpenHack API
- OpenHack's public-facing infrastructure
How to Report
Please send vulnerability reports to security@openhack.com with:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any supporting evidence (screenshots, proof of concept)
What to Expect
- Acknowledgment: We will acknowledge receipt of your report within 2 business days.
- Assessment: We will investigate and validate the reported vulnerability within 5 business days.
- Resolution: We aim to resolve confirmed vulnerabilities within 30 days, depending on severity and complexity.
- Communication: We will keep you informed of our progress throughout the process.
Safe Harbor
We consider security research conducted consistent with this policy to be:
- Authorized concerning any applicable anti-hacking laws
- Authorized concerning any relevant anti-circumvention laws
- Exempt from restrictions in our Terms of Service that would interfere with conducting security research
We will not pursue civil action or initiate a complaint to law enforcement for accidental, good-faith violations of this policy.
Guidelines
We ask that you:
- Do not access, modify, or delete data belonging to other users
- Do not degrade the performance or availability of our services
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it
- Act in good faith to avoid privacy violations and disruptions to our users
Out of Scope
The following are generally not considered vulnerabilities under this policy:
- Social engineering attacks against our employees
- Physical security issues
- Denial of service attacks
- Spam or social engineering via email
- Issues in third-party applications or services not under our control
Recognition
We appreciate responsible disclosure and are happy to acknowledge researchers who report valid vulnerabilities, with their permission.
Contact
Email: security@openhack.com