Legal & Compliance
Vulnerability Disclosure Policy
A safe, coordinated channel for good-faith security research.
Effective and last updated: July 13, 2026
Reporting
Report suspected vulnerabilities to security@heossi.com with the affected asset, reproduction steps, impact, evidence, and a safe contact method. Do not include personal data, credentials, secrets, or exploit code beyond what is necessary to demonstrate the issue. We aim to acknowledge a report within five business days, but response and remediation time depend on severity and complexity.
Authorised good-faith research
- Test only systems you own or HEOSSI public assets clearly in scope; stop immediately if you encounter personal, customer, confidential, or classified data.
- Use the minimum interaction necessary to confirm the issue. Do not persist, pivot, exfiltrate, alter, delete, degrade, phish, socially engineer, access physical premises, or affect other users.
- Do not conduct denial-of-service, traffic flooding, malware deployment, credential attacks, automated high-volume scanning, supply-chain attacks, or testing of third-party services without their permission.
- Keep the report confidential until HEOSSI confirms remediation or agrees to disclosure. Do not demand payment or threaten disclosure; no bounty is promised unless agreed in writing before testing.
Safe-harbour statement
Where research follows this policy, is lawful, avoids harm, and is reported promptly, HEOSSI will not initiate legal action solely for that research. This statement cannot authorise conduct against third parties, waive another person's rights, bind law enforcement, or protect accidental or intentional misconduct outside this policy.
Excluded reports
Reports limited to missing headers without demonstrated impact, self-XSS, clickjacking on pages without sensitive actions, version disclosure, rate-limit observations without bypass impact, social engineering, spam, or findings produced only by automated scanners may be closed without remediation.