Hakuya

Security

Report a security issue.

If you believe a Hakuya service has a security weakness, email sales@hakuya.io. Put “Security report” in the subject.

What to send

Describe the affected hostname or feature, the impact you observed, and the smallest set of steps needed to reproduce it. Include the date and time in UTC when useful. Do not include secrets or personal data in the initial message. We will arrange a safer exchange if supporting material is needed.

Testing boundaries

Do not disrupt availability, use social engineering, access another person’s data, alter production records, send unsolicited messages, or test third-party systems. Stop when a test could expose data or affect another user, and report what you found.

Coordinated handling

Give us a reasonable opportunity to investigate and correct the issue before publishing technical details. We will use the report only to investigate, reproduce, and remediate the suspected weakness. This page does not create a bug bounty or authorize activity that would otherwise be unlawful.