Vulnerability Disclosure Policy
Report security issues responsibly. We review valid submissions, acknowledge them promptly, and work with researchers to improve security.
How to report a vulnerability
Send a clear summary, the affected asset, reproduction steps, impact, and any screenshots or logs. We prefer reports by email, but you may also use the contact page if needed.
Report details
- Target URL, product, or asset name
- Description of the issue and impact
- Step-by-step proof of concept
- Evidence such as screenshots, logs, or payloads
- Your preferred contact details
What to avoid
Do not include destructive payloads, automated flooding, or data exfiltration. Stay within scope, avoid privacy violations, and report findings responsibly.
Response timeline
- Acknowledgement: within 3 business days
- Initial triage: within 7 business days
- Fix coordination: based on severity and scope
- Public disclosure: only after coordination
Safe Harbor
If you act in good faith, avoid privacy violations, do not modify data, and do not disrupt services, Hack4Bug will not pursue legal action against you for the report itself.
InScope
Out of Scope
Leader Board
Recognizing verified researchers who submitted high-impact reports.
Leaderboard rules
- Ranks are assigned by points, highest first.
- Only `1st`, `2nd`, and `3rd` use suffixes. `4` and above are shown as plain numbers.
- The first three ranked reports are highlighted as `Top 1`, `Top 2`, and `Top 3`.
- If two people report the same vulnerability, the first valid report gets the higher score.
- Duplicate reports are still featured on the leaderboard, but with reduced points.
- Example: if the original report is worth 10 points, a duplicate report can receive 5 points.
| Rank | Researcher | Top | GitHub | Verified Reports | Points |
|---|
Leaderboard entries are updated after verification and are shown as researcher handles until public names are approved.