WarmHawk
Security

Coordinated disclosure policy

WarmHawk welcomes good-faith security research into the marketing site, the Stripe checkout/webhook path, the WarmHawk Connect mailbox sign-in relay, and the open-core warmhawk-core-engine codebase. Report findings to security@warmhawk.com — confirmed issues get a response within 1 business day (4 hours if critical), and non-destructive, in-scope testing is covered by the safe-harbor terms below.

This page is the human-readable counterpart to /.well-known/security.txt (RFC 9116), which points machine readers at the same reporting address.

Scope

In scope for reports:

  • •The warmhawk.com marketing site — this site itself, including its forms and public-facing tools.
  • •The Stripe checkout/webhook path — Checkout Session creation, the Customer Portal integration, and the /api/stripe/webhook signature-verification and license-issuance flow.
  • •The WarmHawk Connect relay — /api/connect/* and /connect/*/callback: the license check, the signed ticket that pins each sign-in to one install’s address, and the Google token pass-through.
  • •The open-core warmhawk-core-engine codebase, once public — the sending, queueing, and API engine itself.

A customer’s own self-hosted deployment is generally that customer’s own responsibility to patch and keep current via warmhawk update. That said, a genuine vulnerability in the product itself — found on a self-hosted instance but rooted in how WarmHawk ships — is still welcome and in scope. If you’re unsure which bucket a finding falls into, report it anyway and we’ll sort it out.

How to report

Email security@warmhawk.com with as much detail as you can provide: the affected component, steps to reproduce, and the impact you believe it has. Screenshots, request/response captures, and a proof-of-concept (non-destructive only) all help us triage faster.

No PGP key is published yet. Reports over plain email are fine in the meantime — avoid including live credentials or customer data in the report itself.

Response-time commitment

Confirmed security issues get the same response-time commitment as Tier 1’s support SLA: first response within 1 business day, or within 4 business hours for anything critical. We’ll keep you updated as triage and a fix progress, and we’ll credit your report (if you’d like) once it’s resolved.

Safe harbor

WarmHawk will not pursue legal action against good-faith security researchers who test within the scope above, avoid destructive actions (no data deletion, no service disruption, no accessing another user’s data beyond what’s needed to demonstrate a finding), and report responsibly — privately, to security@warmhawk.com, giving us reasonable time to fix an issue before any public disclosure.

Explicitly out of scope

  • ×Social engineering against WarmHawk staff (phishing, pretexting, or similar, targeting employees or contractors).
  • ×Physical security of any office, data center, or device.
  • ×Denial-of-service testing against production infrastructure, including load testing without prior written permission.