Responsible Disclosure Policy
MalHunterAI welcomes reports of security vulnerabilities affecting our own website, email infrastructure or published work. This page explains how to report an issue and what to expect from us.
How to report
Email [email protected] with a description of the issue, steps to
reproduce and any relevant proof of concept material. Please do not include sensitive
data (credentials, personal information) in your initial report.
What to expect
- Acknowledgement of your report within a reasonable timeframe.
- An honest assessment of severity and where applicable, a remediation timeline.
- Credit in any public write-up, if you'd like it, once the issue is resolved.
Safe harbor
We will not pursue legal action against researchers who make a good faith effort to comply with this policy: avoid privacy violations, service disruption and data destruction. Only interact with accounts and data you own or have explicit permission to test and give us a reasonable opportunity to remediate before any public disclosure.
Out of scope
- Denial of service testing against our infrastructure.
- Social engineering of MalHunter AI staff or third parties.
- Automated scanning that generates significant traffic without prior coordination.
PGP
A PGP key for encrypted reports to [email protected] will be published
here once available.