Legal

Security disclosure

Found a vulnerability in our site? Tell us responsibly — here’s how.

Scope

This policy covers vulnerabilities in HackedWire’s own web properties (hackedwire.com). It does not authorize testing of anyone else’s systems.

How to report

Write to tips@hackedwire.com with “SECURITY” in the subject line. Include:

  • A description of the vulnerability and where you found it (URL, page, feature).
  • Steps to reproduce, without causing harm.
  • Your assessment of impact, and any proof-of-concept kept to the minimum necessary.

Ground rules

  • Do no harm: no data exfiltration beyond what is needed to demonstrate the issue, no degradation of service, no accessing other users’ data.
  • Coordinated disclosure: give us a reasonable opportunity to fix the issue before any public disclosure. We will acknowledge receipt and keep you updated on remediation.
  • We do not currently operate a paid bug-bounty program; reports are handled on a good-faith, coordinated basis.

What we promise

Good-faith researchers who follow this policy will not face legal action from us for their research. Reports are reviewed as they arrive, and verified fixes are deployed promptly.