Vulnerability disclosure policy

Responsible Disclosure Program

XHack is committed to the security of our platform and the privacy of our users. We welcome responsible security research conducted in accordance with this policy. If you believe you have found a security vulnerability, we encourage you to report it to us.
Responsible Disclosure
CVSS 8.0+ Reward
No Cash Reward
Hall of Fame
XHack AI, Elite Plan
CVSS 8.0+

Any accepted vulnerability with a CVSS score of 8.0 or above will be rewarded with one month of free access to the XHack AI Agent on the Elite plan ($150/mo value). Yes, we do offer something.

Subject to validation and acceptance by the XHack security team.
Strict Policy, Do Not Engage Customers

Under no circumstances should any testing activity interact with, access, modify, or impact real customer accounts, data, or sessions. Any researcher found violating this policy will be permanently disqualified and may face legal action. This is a zero-tolerance policy.


No user is authorized to test. If you wish to conduct security research on XHack, you must first request a dedicated demo/test account by contacting us at support@xhack.io. All testing must be performed exclusively on the provided test account. Unauthorized testing will not be accepted and may result in legal consequences.

Scope

Authorized Testing Targets

Only the following targets are in scope. Any testing outside these domains is strictly prohibited and will not be considered under this policy.

Marketing site
https://xhack.io/*
Application
https://app.xhack.io/*
API
https://api.xhack.io/*
Everything Else Is Out of Scope

Any domain, subdomain, IP address, service, or infrastructure not explicitly listed above is strictly out of scope. Testing against out-of-scope targets will not be acknowledged.

Rules and eligibility

Submission Requirements

All submissions must meet the following criteria to be considered valid. Failure to comply with any of these rules will result in immediate disqualification.

Acceptance Criteria

Vulnerability must be unique and not a duplicate of a previously reported or already-known issue

Vulnerability must be within the defined scope: xhack.io, app.xhack.io or api.xhack.io only

You must PROVE the vulnerability is real and exploitable, a working proof-of-concept, not a theoretical or hypothetical finding

The impact must be genuine, not self-inflicted: self-XSS, issues that only affect your own account/session, or anything you caused yourself do not qualify

No real customer data, accounts, or sessions may be accessed, modified, or impacted during testing

Include the identifying header X-Researcher: <your-handle> on all testing traffic so we can tell your research apart from a real attack

Provide clear, reproducible steps with proof-of-concept, screenshots, a short video, or the exact HTTP requests

Minimum CVSS score of 3.0, we do not accept vulnerabilities below this threshold

Exclusions, Not Accepted

Self-XSS (XSS that only affects the attacker's own session)

Missing security headers without demonstrated impact

CSRF on logout or non-sensitive actions

Clickjacking on pages with no sensitive actions

Rate limiting issues without demonstrated business impact

Vulnerabilities in third-party dependencies without a working exploit

Social engineering or phishing attacks against employees or customers

Physical attacks or attacks requiring physical access

Denial of Service (DoS/DDoS) attacks

Automated scanner output without manual validation

Vulnerabilities requiring unlikely user interaction

Content spoofing or text injection without demonstrated impact

Rules of engagement

How to Test Safely

Follow these rules while testing. They keep your research authorized, distinguishable from a real attack, and covered under our safe-harbour terms.

Identify your testing traffic, required

Send this HTTP header with every request you make while testing, so our monitoring can tell your authorized research apart from a genuine attack:

X-Researcher: <your-handle>
Use the same handle you report under. Unidentified traffic that triggers our defenses may be blocked and will not receive safe-harbour consideration.
Identify your traffic

Send the header X-Researcher: <your-handle> with every request while testing. It separates authorized research from a genuine attack and keeps you covered under our safe-harbour terms.

Test only what is in scope

Only xhack.io, app.xhack.io and api.xhack.io are in scope. Do not touch any other host, sub-processor, or third-party service.

Use your own test data

Create your own accounts and test data. Never access, alter, or exfiltrate another user’s data — stop the moment you can demonstrate impact.

Do no harm

No DoS/DDoS, no destructive actions, no volumetric hammering. Keep any automated testing to a reasonable rate.

Report, do not pivot

If you reach sensitive data or critical impact, stop and report it. Do not escalate, persist, or move laterally beyond what proves the finding.

Rewards

Recognition & Rewards

XHack does not offer monetary compensation for vulnerability reports. However, we recognize and reward impactful contributions.

No Cash Rewards

This program does not offer monetary bounties, payouts, or any form of financial compensation for reported vulnerabilities.

CVSS 8.0+
XHack AI, Elite Plan

Any accepted vulnerability with a CVSS score of 8.0 or above will be rewarded with one month of free access to the XHack AI Agent on the Elite plan ($150/mo value).

Subject to validation and acceptance by the XHack security team.
Hall of Fame Recognition

All accepted reports are publicly acknowledged in our Hall of Fame below. Researchers receive full credit with their name and contribution details.

Hall of fame

Recognized Security Researchers

No externally-reported vulnerability has been accepted yet, this list is empty, and we will not invent names to fill it. Be the first to make it here.

No accepted vulnerabilities yet

No one has reported a valid, in-scope vulnerability to us so far. This Hall of Fame is intentionally empty until a real report is accepted, we will never list fictitious researchers. The first name here could be yours.

Submission process

How to Submit a Report

Send your vulnerability report via email following the template below. Incomplete submissions will be rejected.

Email Your Report

Send your complete vulnerability report to:

support@xhack.io
Report Template, Copy & Use
Subject: [VDP] Vulnerability Report, [Brief Title]

To: support@xhack.io

---

1. RESEARCHER INFORMATION
   - Name / Alias: [Your Name or Handle]
   - Email: [Your Contact Email]
   - PGP Key (optional): [Link or Fingerprint]

2. VULNERABILITY DETAILS
   - Title: [e.g., Stored XSS in User Profile Bio]
   - Affected Target: [e.g., https://xhack.io/settings/profile]
   - Vulnerability Type: [e.g., Stored Cross-Site Scripting (XSS)]
   - OWASP Category: [e.g., A7:2017, Cross-Site Scripting]
   - CVSS Score: [e.g., 8.1]
   - CVSS Vector: [e.g., CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N]

3. DESCRIPTION
   [Provide a detailed description of the vulnerability,
    including what the issue is, why it matters, and the
    potential business impact.]

4. STEPS TO REPRODUCE
   Step 1: [Navigate to ...]
   Step 2: [Enter payload ...]
   Step 3: [Observe that ...]
   Step 4: [...]

5. PROOF OF CONCEPT
   [Attach screenshots, screen recordings, HTTP request/
    response logs, or working exploit code. Redact any
    sensitive data.]

6. IMPACT ASSESSMENT
   [Describe the worst-case scenario if this vulnerability
    were exploited by a malicious actor. Include affected
    users, data exposure, and business impact.]

7. SUGGESTED REMEDIATION (optional)
   [If you have recommendations for fixing the issue,
    include them here.]

---

By submitting this report, I confirm that:
- I have NOT accessed, modified, or exfiltrated real customer data
- I used only the authorized test account provided by XHack
- My testing was limited to in-scope targets
- I agree to keep details confidential until authorized

Safe harbour

Legal Protections & Guidelines

Safe Harbour

Researchers who follow this policy in good faith will not face legal action from XHack. We consider security research conducted in compliance with this policy to be authorized, lawful, and beneficial. We will not pursue civil or criminal claims against researchers who adhere to this policy.

Confidentiality

You must not publicly disclose any vulnerability details until we have confirmed remediation and provided written authorization. Premature disclosure will void safe harbour protections and may result in legal action. Coordinated disclosure timelines will be agreed upon on a case-by-case basis.

Our Commitment

XHack commits to acknowledging receipt of your report within 5 business days, providing an initial assessment within 15 business days, and keeping you informed of remediation progress. We will credit researchers in our Hall of Fame unless anonymity is requested.

Ready to Report a Vulnerability?

Request a demo account first, then follow the submission template. We take every report seriously and respond within 5 business days.