Skip to content

05 Security


Reporting a security issue.

We practice what we assess. If you have found a weakness in a HavocSec system, we want to hear about it.

Disclosure

  • Report through a GitHub security advisory on the relevant repository, or initially through LinkedIn. Include steps, impact, and any proof of concept.
  • We follow coordinated disclosure and will credit researchers who ask for it, once a fix is live.
  • Please avoid automated scanning, denial of service, spam, social engineering, and physical attacks against our systems.

Scope

havocsec.me In scope
havocsec.dev In scope
Third-party services we use Out of scope

Unauthorized testing of HavocSec systems is not permitted. The same rule we apply to our own work applies here: explicit authorization, agreed scope.