Security
Report a security issue.
If you believe a Hakuya service has a security weakness, email sales@hakuya.io. Put “Security report” in the subject.
What to send
Describe the affected hostname or feature, the impact you observed, and the smallest set of steps needed to reproduce it. Include the date and time in UTC when useful. Do not include secrets or personal data in the initial message. We will arrange a safer exchange if supporting material is needed.
Testing boundaries
Do not disrupt availability, use social engineering, access another person’s data, alter production records, send unsolicited messages, or test third-party systems. Stop when a test could expose data or affect another user, and report what you found.
Coordinated handling
Give us a reasonable opportunity to investigate and correct the issue before publishing technical details. We will use the report only to investigate, reproduce, and remediate the suspected weakness. This page does not create a bug bounty or authorize activity that would otherwise be unlawful.