Legal

Vulnerability Disclosure Policy

HardLabs welcomes good-faith reporting of security vulnerabilities.

Reports should be sent to:

adam@hardlabs.io

Please include:

  • affected endpoint or component;
  • reproduction steps;
  • expected security impact;
  • relevant evidence;
  • contact information.

Responsible Testing

Security researchers should:

  • avoid accessing another user's or customer's information;
  • stop testing if confidential Customer Content is encountered;
  • avoid destroying or modifying data;
  • avoid denial-of-service attacks;
  • avoid social engineering;
  • avoid phishing;
  • avoid physical attacks;
  • minimize collection of personal or confidential information;
  • provide HardLabs reasonable time to investigate before public disclosure.

Good-Faith Research

HardLabs does not intend to pursue legal action against a researcher solely for accidental, good-faith violations of this policy where the researcher:

  • acts responsibly;
  • avoids harm;
  • does not exploit information obtained;
  • reports the issue promptly;
  • complies with applicable law.

This policy does not authorize testing of third-party services that HardLabs does not control.

Rewards

Reporting a vulnerability does not create an entitlement to payment or another reward.

Any future bug-bounty program will be governed by separate terms.