Vulnerability Disclosure Policy

Found a security issue? Here is how to tell us, and what to expect.

Scope

This policy covers the public website hhivp.com (and www.hhivp.com) and the services we operate for our own use under the hhivp.com domain.

Systems that belong to our clients are out of scope, even where we administer them. Please do not test third-party infrastructure on our behalf; if you believe a client system is affected, contact us and we will coordinate with the owner.

How to report

  • Email security@hhivp.com (fallback: info@hhivp.com).
  • Include the affected URL or host, steps to reproduce, the impact as you understand it and, if relevant, a proof of concept. Screenshots and request/response captures help.
  • Write in English or Russian. Machine-readable contact details are published in /.well-known/security.txt (RFC 9116).

What we commit to

  • Acknowledge your report within 3 business days.
  • Give you an initial assessment (confirmed, not reproducible or out of scope) within 10 business days.
  • Fix confirmed issues on a timeline proportional to their severity, and tell you when the fix is live.
  • Credit you publicly if you wish, or keep the report confidential if you prefer.

We are a small team and do not run a paid bug bounty programme.

Rules of engagement

Please do: test only against in-scope systems, stop as soon as you have enough evidence to demonstrate the issue, and give us reasonable time to fix it before any public disclosure (we ask for 90 days).

Please do not: run denial-of-service or volumetric tests, access or modify data that is not your own, use social engineering against our staff or clients, or pivot from a finding into further exploitation.

Safe harbour

Research conducted in good faith and in line with this policy is authorised. We will not pursue legal action against you for it, and if a third party does, we will make it known that your actions were conducted under this policy.

Last updated: 17 September 2026