leethack
ProblemsPathsLeaderboardPricing
Start free

Security Policy

Responsible Disclosure

We take security seriously — it's literally what we teach. If you discover a vulnerability in Leethack, please report it responsibly by emailing security@leethack.io.

What to include

  • Description of the vulnerability and its potential impact
  • Steps to reproduce (a minimal PoC is ideal)
  • Affected endpoint, route, or component
  • Your contact information for follow-up

Our commitments

  • Acknowledge receipt within 48 hours
  • Keep you informed of our investigation progress
  • Credit researchers in our security advisories (if desired)
  • Not pursue legal action for good-faith research

Out of scope

  • Volumetric denial-of-service attacks
  • Social engineering or phishing of Leethack staff
  • Vulnerabilities in third-party services we depend on
  • Reports generated purely by automated scanners with no manual validation

Contact

security@leethack.io

PGP key available on request. Machine-readable policy at /.well-known/security.txt