05 Security
Reporting a security issue.
We practice what we assess. If you have found a weakness in a HavocSec system, we want to hear about it.
Disclosure
- Report through a GitHub security advisory on the relevant repository, or initially through LinkedIn. Include steps, impact, and any proof of concept.
- We follow coordinated disclosure and will credit researchers who ask for it, once a fix is live.
- Please avoid automated scanning, denial of service, spam, social engineering, and physical attacks against our systems.
Scope
havocsec.me In scope
havocsec.dev In scope
Third-party services we use Out of scope
Unauthorized testing of HavocSec systems is not permitted. The same rule we apply to our own work applies here: explicit authorization, agreed scope.