Security Vulnerability Disclosure Policy
Last updated: 2026-07-14
Introduction
Hypherdyne is committed to the security of our systems and the protection of our users' data. We value the work of the security research community and welcome the responsible, good-faith disclosure of vulnerabilities discovered in our services. This policy describes how to report a security issue to us, what you can expect in return, and the conditions under which we operate a coordinated vulnerability disclosure process.
Scope
The following targets are in scope for this policy:
hypherdyne.comand all subdomainshypherdyne.com.brand all subdomains
The following are explicitly out of scope:
- Third-party services and infrastructure we rely on but do not control (for example, Cloudflare and other hosting or CDN providers).
- Social media accounts and other third-party platforms.
- Denial-of-service (DoS), distributed denial-of-service (DDoS), and volumetric or resource-exhaustion attacks.
- Social engineering of Hypherdyne staff, contractors, or users (including phishing).
- Physical attacks against offices, facilities, or personnel.
- Spam, mass-mailing, or unsolicited bulk messaging.
If you are unsure whether a target or technique is in scope, contact us before testing.
Safe Harbor
We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorized, beneficial, and conducted in good faith. We will not pursue or support legal action against researchers who:
- Make a good-faith effort to comply with this policy;
- Avoid privacy violations, data destruction, and disruption of our services; and
- Report any vulnerability they discover promptly and do not exploit it beyond the minimum necessary to demonstrate the issue.
If legal action is initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known. This safe harbor does not apply to activity that violates the law or that exceeds the scope and guidelines described here.
How to Report
Please send vulnerability reports by email to our security team:
[email protected]We support encrypted email on request. If you would like to send an encrypted report, contact us at the address above and we will provide a PGP public key or arrange a secure channel before you share sensitive details.
For an end-to-end encrypted channel, you can also reach us on Signal at @hypherdyne.32.
What to Include in a Report
To help us triage and remediate quickly, please include as much of the following as possible:
- The affected URL, endpoint, or component.
- Clear, step-by-step instructions to reproduce the issue.
- A description of the impact and a realistic attack scenario.
- Any proof-of-concept (PoC) code, requests, payloads, or screenshots that demonstrate the vulnerability.
- Your contact details and how you would like to be credited, if at all.
Our Response Commitment
When you submit a report in accordance with this policy, you can expect the following:
- Acknowledgement of your report within 5 business days.
- Triage and an initial status update within 10 business days.
- A remediation timeline communicated on a case-by-case basis, depending on the severity and complexity of the issue.
We will keep you informed of our progress and let you know when the issue has been resolved.
Guidelines for Researchers
While researching, we ask that you observe the following guidelines:
- Do not access, modify, exfiltrate, or destroy data that does not belong to you.
- Do not violate the privacy of our users, staff, or any other person.
- Do not disrupt, degrade, or interrupt our services (no DoS or volumetric testing).
- Use only your own accounts and test data; do not interact with accounts you do not own without explicit permission.
- Give us a reasonable amount of time to investigate and remediate before any public disclosure. We suggest a coordinated disclosure window of 90 days from your initial report, or sooner by mutual agreement.
Recognition
We are grateful to the researchers who help keep Hypherdyne and our users safe. With your consent, we are happy to publicly credit you for your responsible disclosure. Let us know in your report how you would like to be named, or if you prefer to remain anonymous.