Responsible reporting
Security policy
Report a vulnerability in the Labs website or an accidental exposure of material that should not be public.
Contact
Email info@hecavex.com with the affected URL, impact and the minimum steps needed to reproduce the issue. The canonical machine-readable policy is security.txt. Lithuanian and English reports are accepted.
In scope
- Security vulnerabilities affecting pages or browser-side code served from
labs.hecavex.com. - Accidental publication of credentials, personal data, private notes, victim data, malware samples or quarantined observations.
- A public dataset bypassing the publication boundary described in the data catalogue.
Do not send through public issues
Do not post credentials, personal data, exploit details, malware or unpublished research in a public GitHub issue. Do not access data beyond what is necessary to demonstrate the problem, disrupt the service, perform denial-of-service testing or test third-party systems linked from Labs.
Editorial corrections
Incorrect source interpretation, attribution, dataset content or analytical conclusions are editorial corrections rather than website vulnerabilities. Send them through the HECAVEX contact channel and include supporting evidence.
Response boundary
HECAVEX is a solo, best-effort research project and does not promise a response SLA or bounty. Good-faith reports will be handled as availability and severity permit.