§ Security

Responsible disclosure.

If you believe you have found a security issue in the SecHive.ai website or a public SecHive artifact, report it privately through the public contact address.

Scope

  • In scope. The public SecHive.ai website and SecHive-published public artifacts.
  • Out of scope. Third-party services, maintainers' systems, restricted research environments, and any system not owned by the reporter or explicitly authorized for testing.

How to report

  1. Email [email protected] with a clear description, minimal reproduction steps, and impact.
  2. Do not include secrets or unnecessary personal data in an initial message.
  3. Coordinate timing privately before public disclosure.

Coordinated disclosure

I acknowledge good-faith reports and coordinate remediation and publication timing privately. When a finding affects a third-party project, service, or maintainer, the reporter must follow that party's authorization and disclosure process and avoid public disclosure before coordination.

Safe harbor

This page does not authorize testing of systems. Research must remain within systems you own or are explicitly authorized to test. Good-faith reports about the public site are welcome, but no legal safe-harbor promise is made on behalf of third parties.

What I ask

  • Do not attempt to access restricted research systems or disclosure records.
  • Do not exfiltrate data beyond what is necessary to prove the issue.
  • Do not run automated load against production endpoints.
  • Coordinate with me before public disclosure so remediation and publication timing can be handled responsibly.

Acknowledgements

Public credit may be offered for confirmed reports with the reporter's consent. No publication schedule or reward is promised.

How SecHive research is disclosed

The section above covers reports coming in. This one covers the research going out, because the same standard has to apply in both directions.

Research is coordinated privately with maintainers and vendors. Public technical material is released only when disclosure status permits, with emphasis on reproducible evidence, remediation validation, and regression prevention. Where a coordinator publishes an advisory but withholds the proof of concept, only the public summary is published here — a public CVE summary is not permission to reproduce a still-withheld reproducer, and a scheduled release date is not the same as a release.

Where a maintainer chooses to publish a deliberately brief advisory, the write-up stays at that level rather than becoming the detailed disclosure the maintainer declined to make. Where an advisory credits multiple reporters, that shared attribution is preserved rather than presented as sole credit. Upstream kernel pages separate Reported-by credit from patch authorship.

Work still under coordination. Additional assigned and reserved vulnerability records remain under coordinated disclosure and are intentionally omitted until publication is authorized. No identifier, product, component or technique from that set appears anywhere on this site. As of 2026-09-05 that set numbers 8 assigned or reserved records; the aggregate is published, the contents are not.