Report a vulnerability
We test other organizations’ security for a living, so we hold our own site to the same standard.
If you find a security issue in hacknow.com, tell us and we’ll work with you to fix it.
How to report
Email chris@hacknow.com with “Security report” in the subject line. Please include:
- the page, endpoint, or component affected;
- what an attacker could do with the issue;
- steps to reproduce it, with any requests, proof-of-concept code, or screenshots;
- whether and how you’d like to be credited.
If you’d like to send details over an encrypted channel, say so in your first email and we’ll set one up.
What you can expect from us
- We’ll confirm we received your report within one business day.
- We’ll tell you whether we could reproduce the issue and keep you updated until it’s fixed.
- With your permission, we’ll thank you by name or handle on this page once the fix is live.
- We don’t pay rewards for reports.
Safe harbor
If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and HackNow will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.
We can only authorize testing of systems HackNow controls. We can’t give permission to test our providers’ platforms, which are listed under “Out of scope.”
In scope
- hacknow.com and www.hacknow.com
- The contact form and its endpoint, /api/contact
Out of scope
- Cloudflare’s platform, including /cdn-cgi/ paths. Report those to Cloudflare’s bug bounty program.
- Google Workspace, including our email service. Report those to Google Bug Hunters.
- Phishing or other social engineering of anyone at HackNow or anyone we work with.
- Denial-of-service, load, or volume testing.
- Reports from automated scanners that don’t show a real security impact.
Rules for testing
- Don’t access, change, or delete data that isn’t yours. If you come across personal or confidential information, stop, don’t keep it, and tell us.
- Exploit an issue only as far as you need to confirm it. Don’t establish persistence or use the issue to reach other systems.
- Keep automated testing slow: no more than 1 request per second.
- Send the contact form no more than 5 times, and start each test message with “VDP test” so we can tell it apart from real requests.
- Give us 90 days from your report to fix the issue before you disclose it publicly. If we fix it sooner, we’ll tell you, and we’re glad to coordinate disclosure with you.
Questions
Not sure whether something is in scope? Email chris@hacknow.com before you test. This policy is also referenced in machine-readable form at /.well-known/security.txt. Effective October 8, 2026.