All policies

Responsible Disclosure

Last updated: July 31, 2026 · Version 1.0.0

If you find a security vulnerability in Hack n Roll, we want to hear from you. This page explains how to report issues safely and in good faith.

1. Overview

We take the security of Hack n Roll seriously. If you discover a vulnerability in our Platform, infrastructure, or services, please report it responsibly so we can investigate and remediate it.

This policy applies only to security research against Hack n Roll systems, services, and infrastructure that Hack n Roll operates or controls. It does not authorize testing of third-party providers such as hosting, CDN, email, or other infrastructure vendors.

We appreciate good-faith security research that helps protect our users and the community.

2. How to Report

Send your report to security@hacknroll.dev with as much detail as possible:

  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce the issue, including URLs, request details, or proof-of-concept code where applicable.
  • Your assessment of severity (optional but helpful).
  • Your contact information, if you would like follow-up communication.

Preferred contact details and reporting practices may also be published at /.well-known/security.txt.

3. Good-Faith Research

We ask that all security research be conducted in good faith. When testing, please:

  • Do not access, modify, or exfiltrate data belonging to other users beyond what is minimally necessary to demonstrate the vulnerability.
  • If you accidentally access personal data, stop testing, avoid further access or copying, and include only the minimum information necessary in your report.
  • Stop testing once you have enough evidence to report the issue. Do not continue exploiting the vulnerability.
  • Do not degrade the availability or performance of the Platform (no denial-of-service testing).
  • Do not publicly disclose the vulnerability before allowing reasonable time for investigation and remediation. Please coordinate with us before publishing details.
  • Do not use social engineering against our users, moderators, or service providers.
  • Do not test or exploit third-party services used by Hack n Roll unless explicitly authorized by that provider.

4. Out of Scope

The following are generally out of scope for vulnerability reports under this policy:

  • Issues in third-party services that we do not control (report those directly to the vendor, and do not test them under this policy).
  • Social engineering or physical attacks.
  • Findings from automated scanners without demonstrated impact.
  • Missing security headers or best-practice recommendations without exploitable impact.
  • Intentional vulnerabilities inside challenge environments. Those are part of the educational experience and are not considered vulnerabilities in Hack n Roll.

Challenge design issues (intentionally vulnerable targets) differ from Platform security issues (bugs in Hack n Roll itself). Report Platform issues here. For unintended challenge problems that affect fairness, see Challenge Rules.

5. Our Response

We aim to acknowledge reports within a reasonable timeframe and will keep you informed of our progress where contact information is provided. We may ask for additional information to reproduce or validate the issue.

We do not currently operate a formal bug bounty program with monetary rewards. With your permission, we may acknowledge significant contributors at our discretion.