Contact: mailto:security@hoxhunt.com Expires: 2027-01-01T00:00:00.000Z Preferred-Languages: en At Hoxhunt, we take the security of our services very seriously. We recognize that even with significant effort, complex systems may still contain vulnerabilities. Should you identify a potential vulnerability, we kindly ask you to report it to us. Your assistance helps us remediate issues promptly and enhances our overall security posture. We value the work of security researchers and appreciate your help. Please note that we have defined certain types of findings that are not useful or accepted. The following is a non-exhaustive list of common out-of-scope issues: * Theoretical or missing security headers (e.g., DNSSEC, CAA, CSP). * Reports of email spoofing (e.g., missing DMARC/SPF/DKIM). * Cross-Site Request Forgery (CSRF) on unauthenticated, login, or logout endpoints. * Clickjacking on pages that do not involve sensitive actions or state changes. * Text injection or content spoofing without a clear attack vector or impact (e.g., cannot modify HTML/CSS). * Missing 'Secure' or 'HttpOnly' flags on cookies not used for session management or storing sensitive data. * Attacks that depend on Man-in-the-Middle (MITM) or physical access to a user's device. * Vulnerabilities that rely heavily on social engineering tactics. * User or resource enumeration (e.g., usernames, IDs) that does not reveal sensitive information or PII. * Any action that could cause a denial of service (DoS) or disrupt our services. * Broken or 'dead' links. Rules for Testing: * Automated scanning tools must not be used against other customers' Hoxhunt tenants. This activity may disrupt service for other users. * Aggressive scanning can be mistaken for a genuine attack by our monitoring systems, may cause instability, or violate third-party provider terms. * If you intend to use an automated scanner, you must first contact us at security@hoxhunt.com for coordination, and you must confine all testing exclusively to your own Hoxhunt tenant. Attacking other customer environments is strictly prohibited. * When you find a vulnerability, do not exploit it beyond the minimum extent necessary to prove its existence. This means you must not download, modify, or delete any data that is not your own, or access more data than is required for a proof-of-concept. How to Report a Finding: * Email your findings directly to security@hoxhunt.com. * Please include a clear and concise description of the issue. * To help us resolve the issue quickly, provide detailed, step-by-step instructions that allow us to reproduce the vulnerability. Public Disclosure Policy: * To protect our users, please maintain confidentiality. Do not discuss or disclose the vulnerability publicly until we have completed our remediation and notified any impacted parties. * For any public-facing publication (e.g., blog post, conference talk), you must provide us with a draft for review and written approval at least 30 days before your intended publication date. * Your publication must not, under any circumstances, contain: * Any data related to Hoxhunt's customers or their Hoxhunt tenants. * Private information about any Hoxhunt employees, partners, or contractors. Our Commitment to You: * We will provide an initial response to your report (provided that it follows the above guidelines) within a reasonable time, including our assessment and a target timeline for resolution. * We offer safe harbor: we will not pursue legal action against any researcher who adheres to this policy in good faith. * Your report will be treated as confidential. We will not share your personal information with third parties without your explicit consent. * We will provide you with periodic updates as we work to remediate the issue. * When the vulnerability is publicly disclosed, we will credit you for the discovery, unless you prefer to remain anonymous. Our goal is to resolve all security issues efficiently. We aim to collaborate with researchers on any public announcements after a fix is in place.