RESPONSIBLE DISCLOSURE
Report security issues through the right channel.
Hamiltonn Cloud welcomes responsible reports of suspected vulnerabilities and asks researchers to avoid actions that could harm customers, data or service availability.
Hamiltonn Cloud
Report security issues through the right channel.
Responsible disclosure is the process for privately reporting a suspected security vulnerability so Hamiltonn can investigate and remediate it before unnecessary public exposure.
Definition
What does this mean?
Responsible disclosure is the process for privately reporting a suspected security vulnerability so Hamiltonn can investigate and remediate it before unnecessary public exposure.
Hamiltonn Cloud combines reusable software infrastructure, configurable product capabilities and flexible deployment so organisations can build around their own brand and operating model.
REPORT
What to include in a useful report.
- Affected hostname, page, endpoint or product.
- Clear description of the suspected issue.
- Steps needed to reproduce it.
- Observed impact and required conditions.
- Safe supporting evidence without customer data.
- A contact address for follow-up.
BOUNDARIES
Do not create additional harm while testing.
- Do not access or retain customer data that is not yours.
- Do not perform denial-of-service or destructive testing.
- Do not use social engineering.
- Do not publish exploit details before a reasonable investigation opportunity.
- Stop testing if sensitive information appears unexpectedly.
CONTACT
Use the security channel.
Use the responsible disclosure form below to send a private report to the Hamiltonn Cloud team. Avoid sending passwords, private keys or unnecessary customer data.
PRIVATE REPORT
Send a security report.
Use this form for suspected vulnerabilities affecting Hamiltonn Cloud. Do not include passwords, private keys or customer data that is not necessary to explain the issue.
Security report received.
Thank you. The report has been delivered privately for review.
PROCESS
What happens after a report.
Receive
Record the report.
Triage
Assess scope.
Investigate
Reproduce and understand impact.
Mitigate
Apply a fix or containment.
Verify
Confirm resolution.
Close
Communicate the outcome as appropriate.
FAQs
RESPONSIBLE DISCLOSURE FAQs
Where should I report a vulnerability?
Use the Responsible Disclosure form on this page.
Can I test using real customer data?
No. Avoid accessing, changing or retaining data that is not yours.
Is denial-of-service testing allowed?
No, not without explicit written authorisation.
Should I publish immediately?
Report privately first and allow a reasonable investigation and remediation period.
What should the report contain?
Affected service, reproduction steps, impact and safe supporting evidence.
Build on Hamiltonn Cloud.
Choose the product, modules and deployment model that fit your business, then bring the customer experience under your own brand.