Introduction
HypeX Digital Sri Lanka values the security community.
We appreciate the responsible disclosure of vulnerabilities to help us keep our platform and client data safe.
1. Reporting a Vulnerability
If you discover a security issue, email [email protected].
- Provide a clear, technical description of the vulnerability.
- Include step by step instructions to reproduce the issue.
- Identify the potential impact.
- Submit reports in English.
2. Rules of Engagement
To qualify for safe harbor, you must:
- Avoid privacy violations and data destruction.
- Do not degrade our services (no DDoS).
- Do not use social engineering or phishing against our staff or clients.
- Give us a 90 day window to remediate the issue before public disclosure.
3. Scope
- In Scope:
*.hypesrilanka.com. - Out of Scope: Third party services (e.g., WordPress plugins, hosting providers, Google Maps API).
4. Safe Harbor
HypeX Digital Sri Lanka will not pursue legal action against researchers who discover and report vulnerabilities in good faith and comply with this policy.
5. Rewards
We do not offer a financial bug bounty program at this time.
We may offer public acknowledgment on our website for significant, verified findings.