Vulnerability disclosure policy
Responsible Disclosure Program
XHack is committed to the security of our platform and the privacy of our users. We welcome responsible security research conducted in accordance with this policy. If you believe you have found a security vulnerability, we encourage you to report it to us.
XHack AI, Elite Plan
Any accepted vulnerability with a CVSS score of 8.0 or above will be rewarded with one month of free access to the XHack AI Agent on the Elite plan ($150/mo value). Yes, we do offer something.
Subject to validation and acceptance by the XHack security team.Strict Policy, Do Not Engage Customers
Under no circumstances should any testing activity interact with, access, modify, or impact real customer accounts, data, or sessions. Any researcher found violating this policy will be permanently disqualified and may face legal action. This is a zero-tolerance policy.
No user is authorized to test. If you wish to conduct security research on XHack, you must first request a dedicated demo/test account by contacting us at support@xhack.io. All testing must be performed exclusively on the provided test account. Unauthorized testing will not be accepted and may result in legal consequences.
Scope
Authorized Testing Targets
Only the following targets are in scope. Any testing outside these domains is strictly prohibited and will not be considered under this policy.
https://xhack.io/*
https://app.xhack.io/*
https://api.xhack.io/*
Everything Else Is Out of Scope
Any domain, subdomain, IP address, service, or infrastructure not explicitly listed above is strictly out of scope. Testing against out-of-scope targets will not be acknowledged.
Rules and eligibility
Submission Requirements
All submissions must meet the following criteria to be considered valid. Failure to comply with any of these rules will result in immediate disqualification.
Acceptance Criteria
Vulnerability must be unique and not a duplicate of a previously reported or already-known issue
Vulnerability must be within the defined scope: xhack.io, app.xhack.io or api.xhack.io only
You must PROVE the vulnerability is real and exploitable, a working proof-of-concept, not a theoretical or hypothetical finding
The impact must be genuine, not self-inflicted: self-XSS, issues that only affect your own account/session, or anything you caused yourself do not qualify
No real customer data, accounts, or sessions may be accessed, modified, or impacted during testing
Include the identifying header X-Researcher: <your-handle> on all testing traffic so we can tell your research apart from a real attack
Provide clear, reproducible steps with proof-of-concept, screenshots, a short video, or the exact HTTP requests
Minimum CVSS score of 3.0, we do not accept vulnerabilities below this threshold
Exclusions, Not Accepted
Self-XSS (XSS that only affects the attacker's own session)
Missing security headers without demonstrated impact
CSRF on logout or non-sensitive actions
Clickjacking on pages with no sensitive actions
Rate limiting issues without demonstrated business impact
Vulnerabilities in third-party dependencies without a working exploit
Social engineering or phishing attacks against employees or customers
Physical attacks or attacks requiring physical access
Denial of Service (DoS/DDoS) attacks
Automated scanner output without manual validation
Vulnerabilities requiring unlikely user interaction
Content spoofing or text injection without demonstrated impact
Rules of engagement
How to Test Safely
Follow these rules while testing. They keep your research authorized, distinguishable from a real attack, and covered under our safe-harbour terms.
Identify your testing traffic, required
Send this HTTP header with every request you make while testing, so our monitoring can tell your authorized research apart from a genuine attack:
Identify your traffic
Send the header X-Researcher: <your-handle> with every request while testing. It separates authorized research from a genuine attack and keeps you covered under our safe-harbour terms.
Test only what is in scope
Only xhack.io, app.xhack.io and api.xhack.io are in scope. Do not touch any other host, sub-processor, or third-party service.
Use your own test data
Create your own accounts and test data. Never access, alter, or exfiltrate another user’s data — stop the moment you can demonstrate impact.
Do no harm
No DoS/DDoS, no destructive actions, no volumetric hammering. Keep any automated testing to a reasonable rate.
Report, do not pivot
If you reach sensitive data or critical impact, stop and report it. Do not escalate, persist, or move laterally beyond what proves the finding.
Rewards
Recognition & Rewards
XHack does not offer monetary compensation for vulnerability reports. However, we recognize and reward impactful contributions.
No Cash Rewards
This program does not offer monetary bounties, payouts, or any form of financial compensation for reported vulnerabilities.
XHack AI, Elite Plan
Any accepted vulnerability with a CVSS score of 8.0 or above will be rewarded with one month of free access to the XHack AI Agent on the Elite plan ($150/mo value).
Subject to validation and acceptance by the XHack security team.Hall of Fame Recognition
All accepted reports are publicly acknowledged in our Hall of Fame below. Researchers receive full credit with their name and contribution details.
Hall of fame
Recognized Security Researchers
No externally-reported vulnerability has been accepted yet, this list is empty, and we will not invent names to fill it. Be the first to make it here.
No accepted vulnerabilities yet
No one has reported a valid, in-scope vulnerability to us so far. This Hall of Fame is intentionally empty until a real report is accepted, we will never list fictitious researchers. The first name here could be yours.
Submission process
How to Submit a Report
Send your vulnerability report via email following the template below. Incomplete submissions will be rejected.
Report Template, Copy & Use
Subject: [VDP] Vulnerability Report, [Brief Title]
To: support@xhack.io
---
1. RESEARCHER INFORMATION
- Name / Alias: [Your Name or Handle]
- Email: [Your Contact Email]
- PGP Key (optional): [Link or Fingerprint]
2. VULNERABILITY DETAILS
- Title: [e.g., Stored XSS in User Profile Bio]
- Affected Target: [e.g., https://xhack.io/settings/profile]
- Vulnerability Type: [e.g., Stored Cross-Site Scripting (XSS)]
- OWASP Category: [e.g., A7:2017, Cross-Site Scripting]
- CVSS Score: [e.g., 8.1]
- CVSS Vector: [e.g., CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N]
3. DESCRIPTION
[Provide a detailed description of the vulnerability,
including what the issue is, why it matters, and the
potential business impact.]
4. STEPS TO REPRODUCE
Step 1: [Navigate to ...]
Step 2: [Enter payload ...]
Step 3: [Observe that ...]
Step 4: [...]
5. PROOF OF CONCEPT
[Attach screenshots, screen recordings, HTTP request/
response logs, or working exploit code. Redact any
sensitive data.]
6. IMPACT ASSESSMENT
[Describe the worst-case scenario if this vulnerability
were exploited by a malicious actor. Include affected
users, data exposure, and business impact.]
7. SUGGESTED REMEDIATION (optional)
[If you have recommendations for fixing the issue,
include them here.]
---
By submitting this report, I confirm that:
- I have NOT accessed, modified, or exfiltrated real customer data
- I used only the authorized test account provided by XHack
- My testing was limited to in-scope targets
- I agree to keep details confidential until authorizedSafe harbour
Legal Protections & Guidelines
Safe Harbour
Researchers who follow this policy in good faith will not face legal action from XHack. We consider security research conducted in compliance with this policy to be authorized, lawful, and beneficial. We will not pursue civil or criminal claims against researchers who adhere to this policy.
Confidentiality
You must not publicly disclose any vulnerability details until we have confirmed remediation and provided written authorization. Premature disclosure will void safe harbour protections and may result in legal action. Coordinated disclosure timelines will be agreed upon on a case-by-case basis.
Our Commitment
XHack commits to acknowledging receipt of your report within 5 business days, providing an initial assessment within 15 business days, and keeping you informed of remediation progress. We will credit researchers in our Hall of Fame unless anonymity is requested.
Ready to Report a Vulnerability?
Request a demo account first, then follow the submission template. We take every report seriously and respond within 5 business days.