Security Vulnerability Disclosure Policy

Last updated: 2026-07-14

Introduction

Hypherdyne is committed to the security of our systems and the protection of our users' data. We value the work of the security research community and welcome the responsible, good-faith disclosure of vulnerabilities discovered in our services. This policy describes how to report a security issue to us, what you can expect in return, and the conditions under which we operate a coordinated vulnerability disclosure process.

Scope

The following targets are in scope for this policy:

The following are explicitly out of scope:

If you are unsure whether a target or technique is in scope, contact us before testing.

Safe Harbor

We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorized, beneficial, and conducted in good faith. We will not pursue or support legal action against researchers who:

If legal action is initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known. This safe harbor does not apply to activity that violates the law or that exceeds the scope and guidelines described here.

How to Report

Please send vulnerability reports by email to our security team:

[email protected]

We support encrypted email on request. If you would like to send an encrypted report, contact us at the address above and we will provide a PGP public key or arrange a secure channel before you share sensitive details.

For an end-to-end encrypted channel, you can also reach us on Signal at @hypherdyne.32.

What to Include in a Report

To help us triage and remediate quickly, please include as much of the following as possible:

Our Response Commitment

When you submit a report in accordance with this policy, you can expect the following:

We will keep you informed of our progress and let you know when the issue has been resolved.

Guidelines for Researchers

While researching, we ask that you observe the following guidelines:

Recognition

We are grateful to the researchers who help keep Hypherdyne and our users safe. With your consent, we are happy to publicly credit you for your responsible disclosure. Let us know in your report how you would like to be named, or if you prefer to remain anonymous.

Related Resources