Found a security issue? Here is how to tell us, and what to expect.
This policy covers the public website hhivp.com (and www.hhivp.com) and the services we operate for our own use under the hhivp.com domain.
Systems that belong to our clients are out of scope, even where we administer them. Please do not test third-party infrastructure on our behalf; if you believe a client system is affected, contact us and we will coordinate with the owner.
We are a small team and do not run a paid bug bounty programme.
Please do: test only against in-scope systems, stop as soon as you have enough evidence to demonstrate the issue, and give us reasonable time to fix it before any public disclosure (we ask for 90 days).
Please do not: run denial-of-service or volumetric tests, access or modify data that is not your own, use social engineering against our staff or clients, or pivot from a finding into further exploitation.
Research conducted in good faith and in line with this policy is authorised. We will not pursue legal action against you for it, and if a third party does, we will make it known that your actions were conducted under this policy.
Last updated: 17 September 2026