Legal
Vulnerability Disclosure Policy
HardLabs welcomes good-faith reporting of security vulnerabilities.
Reports should be sent to:
Please include:
- affected endpoint or component;
- reproduction steps;
- expected security impact;
- relevant evidence;
- contact information.
Responsible Testing
Security researchers should:
- avoid accessing another user's or customer's information;
- stop testing if confidential Customer Content is encountered;
- avoid destroying or modifying data;
- avoid denial-of-service attacks;
- avoid social engineering;
- avoid phishing;
- avoid physical attacks;
- minimize collection of personal or confidential information;
- provide HardLabs reasonable time to investigate before public disclosure.
Good-Faith Research
HardLabs does not intend to pursue legal action against a researcher solely for accidental, good-faith violations of this policy where the researcher:
- acts responsibly;
- avoids harm;
- does not exploit information obtained;
- reports the issue promptly;
- complies with applicable law.
This policy does not authorize testing of third-party services that HardLabs does not control.
Rewards
Reporting a vulnerability does not create an entitlement to payment or another reward.
Any future bug-bounty program will be governed by separate terms.