Security Disclosure
hoaxeye takes the security of its platform, infrastructure, and customer data seriously. This policy describes how to responsibly report security vulnerabilities to us.
1. Reporting a Vulnerability
If you discover a security vulnerability in any hoaxeye service, website, API, or integration, please report it responsibly to:
When reporting, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact or severity
- Any proof-of-concept code, screenshots, or logs (where applicable)
- Your contact information for follow-up
2. Scope
This policy covers vulnerabilities in:
- The hoaxeye website and web applications
- hoaxeye APIs and backend services
- hoaxeye integrations and server resources
- Authentication and authorization mechanisms
Out of scope:
- Third-party services or integrations not operated by hoaxeye
- Social engineering attacks against hoaxeye employees
- Physical security of infrastructure
- Denial of service (DoS/DDoS) attacks
- Spam or email spoofing
3. Safe Harbor
If you act in good faith and comply with this policy, we will:
- Not pursue legal action against you for your research
- Work with you to understand and resolve the issue
- Acknowledge your contribution (if desired)
Good faith means:
- You do not access, modify, or delete data belonging to other users
- You do not disrupt the availability or performance of the Services
- You report the vulnerability promptly and do not disclose it publicly before we have had a reasonable opportunity to address it
- You do not use the vulnerability for personal gain beyond demonstrating the issue
4. Response
We aim to:
- Acknowledge receipt of your report within 72 hours
- Provide an initial assessment within a reasonable timeframe
- Keep you informed of our progress toward resolution
- Notify you when the issue has been resolved
5. Recognition
We value the security research community. With your permission, we may acknowledge your contribution publicly. We do not currently offer monetary bounties but may do so in the future.
6. Contact
Security reports and questions:
[email protected]