Legal
Security disclosure
Found a vulnerability in our site? Tell us responsibly — here’s how.
Scope
This policy covers vulnerabilities in HackedWire’s own web properties (hackedwire.com). It does not authorize testing of anyone else’s systems.
How to report
Write to tips@hackedwire.com with “SECURITY” in the subject line. Include:
- A description of the vulnerability and where you found it (URL, page, feature).
- Steps to reproduce, without causing harm.
- Your assessment of impact, and any proof-of-concept kept to the minimum necessary.
Ground rules
- Do no harm: no data exfiltration beyond what is needed to demonstrate the issue, no degradation of service, no accessing other users’ data.
- Coordinated disclosure: give us a reasonable opportunity to fix the issue before any public disclosure. We will acknowledge receipt and keep you updated on remediation.
- We do not currently operate a paid bug-bounty program; reports are handled on a good-faith, coordinated basis.
What we promise
Good-faith researchers who follow this policy will not face legal action from us for their research. Reports are reviewed as they arrive, and verified fixes are deployed promptly.