Security Policy
Responsible Disclosure
We take security seriously — it's literally what we teach. If you discover a vulnerability in Leethack, please report it responsibly by emailing security@leethack.io.
What to include
- Description of the vulnerability and its potential impact
- Steps to reproduce (a minimal PoC is ideal)
- Affected endpoint, route, or component
- Your contact information for follow-up
Our commitments
- Acknowledge receipt within 48 hours
- Keep you informed of our investigation progress
- Credit researchers in our security advisories (if desired)
- Not pursue legal action for good-faith research
Out of scope
- Volumetric denial-of-service attacks
- Social engineering or phishing of Leethack staff
- Vulnerabilities in third-party services we depend on
- Reports generated purely by automated scanners with no manual validation
Contact
security@leethack.ioPGP key available on request. Machine-readable policy at /.well-known/security.txt