RESPONSIBLE DISCLOSURE

Report security issues through the right channel.

Hamiltonn Cloud welcomes responsible reports of suspected vulnerabilities and asks researchers to avoid actions that could harm customers, data or service availability.

Hamiltonn Cloud

Report security issues through the right channel.

Responsible disclosure is the process for privately reporting a suspected security vulnerability so Hamiltonn can investigate and remediate it before unnecessary public exposure.

Definition

What does this mean?

Responsible disclosure is the process for privately reporting a suspected security vulnerability so Hamiltonn can investigate and remediate it before unnecessary public exposure.

Hamiltonn Cloud combines reusable software infrastructure, configurable product capabilities and flexible deployment so organisations can build around their own brand and operating model.

REPORT

What to include in a useful report.

  • Affected hostname, page, endpoint or product.
  • Clear description of the suspected issue.
  • Steps needed to reproduce it.
  • Observed impact and required conditions.
  • Safe supporting evidence without customer data.
  • A contact address for follow-up.

BOUNDARIES

Do not create additional harm while testing.

  • Do not access or retain customer data that is not yours.
  • Do not perform denial-of-service or destructive testing.
  • Do not use social engineering.
  • Do not publish exploit details before a reasonable investigation opportunity.
  • Stop testing if sensitive information appears unexpectedly.

CONTACT

Use the security channel.

Use the responsible disclosure form below to send a private report to the Hamiltonn Cloud team. Avoid sending passwords, private keys or unnecessary customer data.

PRIVATE REPORT

Send a security report.

Use this form for suspected vulnerabilities affecting Hamiltonn Cloud. Do not include passwords, private keys or customer data that is not necessary to explain the issue.

Please enter your name.

Please enter a valid email.

Please identify the affected service.

Please describe the issue.

Reports are sent privately to the Hamiltonn Cloud team for triage.

PROCESS

What happens after a report.

Receive

Record the report.

Triage

Assess scope.

Investigate

Reproduce and understand impact.

Mitigate

Apply a fix or containment.

Verify

Confirm resolution.

Close

Communicate the outcome as appropriate.

FAQs

RESPONSIBLE DISCLOSURE FAQs

Where should I report a vulnerability?

Use the Responsible Disclosure form on this page.

Can I test using real customer data?

No. Avoid accessing, changing or retaining data that is not yours.

Is denial-of-service testing allowed?

No, not without explicit written authorisation.

Should I publish immediately?

Report privately first and allow a reasonable investigation and remediation period.

What should the report contain?

Affected service, reproduction steps, impact and safe supporting evidence.

Build on Hamiltonn Cloud.

Choose the product, modules and deployment model that fit your business, then bring the customer experience under your own brand.