§ Security

Responsible disclosure.

If you believe you have found a security issue in the SecHive website, the SecHive platform, or any SecHive-published proof pack, this page is the path. We will respond.

Scope

How to report

  1. Email [email protected] with a clear description, reproduction steps, and impact.
  2. Encrypt sensitive material with our PGP key (fingerprint published on this page; key request over email).
  3. Allow up to 90 days before public disclosure.

Safe harbor

Good-faith research within scope and in compliance with this policy will not result in legal action by SecHive. We will not pursue or support a complaint against you for accessing data or systems no further than necessary to demonstrate the issue, provided you do not exfiltrate, modify or destroy data, and you respect privacy and availability.

What we ask

Acknowledgements

With reporter consent, we credit confirmed external reports in a public hall of fame published quarterly.