Responsible Disclosure Policy
Our Commitment to Security
HRHK Solutions takes the security of our website, services, and client systems seriously. We encourage security researchers and members of the public to responsibly report security vulnerabilities they discover in our website or services. We are committed to working with the security research community to investigate and resolve reported vulnerabilities.
Important: This policy applies only to HRHK Solutions' own website and services. It does not authorize testing of any third-party systems, client systems, or any infrastructure you do not own or have explicit written authorization to assess.
Scope
This policy covers security vulnerabilities discovered in:
- The HRHK Solutions website at https://hrhk.net
- Subdomains of hrhk.net owned and operated by HRHK Solutions
- Public-facing services directly operated by HRHK Solutions
What We Ask
If you discover a security vulnerability, we ask that you:
- Report it privately — Send your findings to [email protected] with "Security Disclosure" in the subject line. Do not disclose the vulnerability publicly until we have had a reasonable opportunity to investigate and address it.
- Provide sufficient detail — Include a description of the vulnerability, steps to reproduce, affected URLs or components, and any relevant technical details that will help us understand and validate the issue.
- Avoid destructive testing — Do not exploit the vulnerability beyond what is necessary to demonstrate its existence. Do not access, modify, or delete data that does not belong to you. Do not disrupt services or degrade performance.
- Respect privacy — Do not access, store, or share personal data belonging to HRHK, our clients, or our users. If you inadvertently encounter such data, do not copy it and report the encounter to us.
What We Commit
When you report a vulnerability in accordance with this policy, we commit to:
- Acknowledge receipt of your report within 5 business days
- Investigate the reported vulnerability and determine its validity and severity
- Communicate with you regarding the status of our investigation and remediation
- Remediate valid vulnerabilities within a reasonable timeframe based on severity
- Provide attribution if you wish to be publicly acknowledged as the reporter (unless you prefer to remain anonymous)
- Not pursue legal action against researchers who comply with this policy
What to Avoid
While investigating vulnerabilities, please avoid:
- Accessing, modifying, or deleting data that does not belong to you
- Disrupting services or degrading performance for other users
- Using social engineering, phishing, or physical security attacks
- Testing third-party systems, services, or applications not owned by HRHK
- Exploiting vulnerabilities beyond what is necessary to demonstrate their existence
- Installing malware, backdoors, or persistent access mechanisms
Reporting Process
To report a security vulnerability:
- Email [email protected]
- Include "Security Disclosure" in the subject line
- Provide a clear description of the vulnerability
- Include steps to reproduce the issue
- Specify affected URLs, endpoints, or components
- Include any relevant technical details or proof-of-concept (non-destructive)
- Indicate whether you wish to be publicly acknowledged or remain anonymous
Timeline
Our general timeline for handling responsible disclosures:
- Acknowledgment: Within 5 business days of receipt
- Initial Assessment: Within 10 business days of acknowledgment
- Remediation: Timeframe depends on severity and complexity; we will communicate our estimated timeline
- Public Disclosure: Coordinated with the reporter after remediation, respecting any agreed-upon timeline
Safe Harbor
HRHK Solutions will not initiate legal action against security researchers who comply with this policy. We consider good-faith security research that follows these guidelines to be valuable contributions to our security posture.
Contact
For security-related inquiries or to report a vulnerability:
- Email: [email protected] (include "Security Disclosure" in subject line)
- Mailing Address: HRHK Solutions, LLC, P.O. Box 868135, Plano, TX 75086, US
This policy may be updated from time to time. The current version is available at this URL.