Coordinated disclosure
When we find a vulnerability during an engagement, it goes to the client first — critical issues immediately, under the escalation clause of the rules of engagement, rather than being saved for the final report.
If in the course of authorised testing we encounter a flaw in a third-party product, we report it to that vendor privately and give them reasonable time to remediate before any public detail is shared. We do not publish exploit code for unpatched issues.
Rules of engagement
Nothing starts without written authorisation naming the in-scope targets, the testing windows, and a traffic identifier your team can filter our activity on. Anything not explicitly in scope is out of scope.
- We test only the assets you own or are contractually permitted to authorise.
- We agree escalation contacts before testing, and page them the moment a critical issue is confirmed.
- We avoid denial-of-service and destructive techniques unless they are explicitly scoped and scheduled.
- We handle any data we encounter as confidential, minimise what we retain, and destroy it on engagement close.
Legal & ethics
Authorisation is what separates security testing from a crime. We will not act against a target without documented permission from a party empowered to grant it, and we will decline work where that authority is unclear — no matter how the request is framed.
If you believe you have found a security issue in our own infrastructure, we welcome the report. Email admin@hack-tech.org with the details and give us reasonable time to respond before disclosing publicly. We will not pursue action against good-faith researchers who follow this process.