Coordinated disclosure policy
WarmHawk welcomes good-faith security research into the marketing site, the Stripe checkout/webhook path, the WarmHawk Connect mailbox sign-in relay, and the open-core warmhawk-core-engine codebase. Report findings to security@warmhawk.com — confirmed issues get a response within 1 business day (4 hours if critical), and non-destructive, in-scope testing is covered by the safe-harbor terms below.
This page is the human-readable counterpart to /.well-known/security.txt (RFC 9116), which points machine readers at the same reporting address.
Scope
In scope for reports:
- •The warmhawk.com marketing site — this site itself, including its forms and public-facing tools.
- •The Stripe checkout/webhook path — Checkout Session creation, the Customer Portal integration, and the
/api/stripe/webhooksignature-verification and license-issuance flow. - •The WarmHawk Connect relay —
/api/connect/*and/connect/*/callback: the license check, the signed ticket that pins each sign-in to one install’s address, and the Google token pass-through. - •The open-core warmhawk-core-engine codebase, once public — the sending, queueing, and API engine itself.
A customer’s own self-hosted deployment is generally that customer’s own responsibility to patch and keep current via warmhawk update. That said, a genuine vulnerability in the product itself — found on a self-hosted instance but rooted in how WarmHawk ships — is still welcome and in scope. If you’re unsure which bucket a finding falls into, report it anyway and we’ll sort it out.
How to report
Email security@warmhawk.com with as much detail as you can provide: the affected component, steps to reproduce, and the impact you believe it has. Screenshots, request/response captures, and a proof-of-concept (non-destructive only) all help us triage faster.
No PGP key is published yet. Reports over plain email are fine in the meantime — avoid including live credentials or customer data in the report itself.
Response-time commitment
Confirmed security issues get the same response-time commitment as Tier 1’s support SLA: first response within 1 business day, or within 4 business hours for anything critical. We’ll keep you updated as triage and a fix progress, and we’ll credit your report (if you’d like) once it’s resolved.
Safe harbor
WarmHawk will not pursue legal action against good-faith security researchers who test within the scope above, avoid destructive actions (no data deletion, no service disruption, no accessing another user’s data beyond what’s needed to demonstrate a finding), and report responsibly — privately, to security@warmhawk.com, giving us reasonable time to fix an issue before any public disclosure.
Explicitly out of scope
- ×Social engineering against WarmHawk staff (phishing, pretexting, or similar, targeting employees or contractors).
- ×Physical security of any office, data center, or device.
- ×Denial-of-service testing against production infrastructure, including load testing without prior written permission.