Disclosure Policy

Coordinated disclosure is preferred. Harmful testing is not.

Hackerman Crew supports good-faith, defensive security research and coordinated disclosure. This page explains the boundaries for public reporting and what should not be sent, published, or attempted.

In scope for disclosure

  • Vulnerabilities discovered through authorized testing, defensive review, or good-faith research.
  • Issues that can be described without publishing exploit code, stolen data, or unsafe reproduction steps.
  • Findings that materially affect confidentiality, integrity, availability, privacy, or trust boundaries.

Out of scope

  • Social engineering, phishing, or physical testing against people or organizations without explicit written authorization.
  • Denial-of-service activity, destructive testing, credential attacks, spam, or bulk scanning against third-party systems.
  • Requests for paid bug bounties, exclusivity, or confidential handling that has not been separately agreed in writing.

Handling

Reports should arrive with enough context to be triaged safely.

  • Reports should be reviewed for legitimacy, risk, and publication safety before any public discussion.
  • The site does not promise a fixed SLA, but good-faith reports should receive a documented triage path once the approved intake channel is published.
  • Publication should wait until the affected party has had a reasonable opportunity to understand and address the issue, unless immediate public warning is ethically necessary.

Current status

Public intake is intentionally controlled.

A public web form is not enabled. The approved intake channel will be published on the contact page before live vulnerability submissions are requested.

AS OF AUGUST 23, 2026, NO BUG BOUNTY OR PAID SUBMISSION PROGRAM IS OFFERED

Review contact guidance