HackerHub8 LLP is committed to maintaining the security and integrity of our systems, applications, and services. We value the contributions of security researchers, ethical hackers, and users who help us identify and address potential vulnerabilities.
This Vulnerability Disclosure Policy provides guidelines for responsibly reporting security issues discovered within HackerHub8 platforms, services, or digital infrastructure.
Our Security Commitment
At HackerHub8 LLP, we actively work to protect our infrastructure and maintain strong cybersecurity practices. Despite rigorous security measures, vulnerabilities may occasionally occur. We encourage responsible disclosure to ensure vulnerabilities are resolved quickly and safely.
We acknowledge new reports within 3 business days.
We provide an initial triage/validity assessment within 10 business days.
We work to remediate confirmed critical and high-severity issues as a priority; timelines depend on complexity.
We maintain open communication with security researchers throughout.
We respect responsible security research conducted in good faith.
Scope
This policy applies to vulnerabilities discovered in the following systems and services operated by HackerHub8 LLP:
In Scope:
hackerhub8.in and its official subdomains
playctf.in — our cybersecurity skilling and CTF platform
Public APIs and web applications we operate
Security products we develop and control (Khetaka, Martinet, Cyber Law AI), excluding client-deployed instances covered by a separate engagement agreement
Out of Scope:
Third-party services we use but do not control (e.g., our payment processor, hosting provider, analytics provider)
Social engineering, phishing, or physical attacks against staff, interns, or facilities
Denial-of-Service (DoS/DDoS) testing or any testing that degrades service availability
Client systems assessed under a signed VAPT/MDR/GRC engagement — report those findings through the engagement's agreed channel, not this policy
Examples of Reportable Vulnerabilities
Authentication bypass
SQL injection
Cross-site scripting (XSS)
Remote code execution
Access control vulnerabilities
Information disclosure
Server misconfiguration
Insecure API access
Non-Qualifying Issues
The following issues are generally not considered security vulnerabilities under this policy:
Spam or social engineering attacks
Issues requiring physical access to a device
Denial-of-Service (DoS) attacks or stress testing
Outdated browser warnings or informational alerts
Reports without sufficient technical details
How to Report a Vulnerability
If you discover a vulnerability affecting HackerHub8 services, please report it responsibly by contacting our security team.
To ensure responsible disclosure, we ask researchers to follow these guidelines:
Report vulnerabilities privately before public disclosure.
Allow reasonable time for HackerHub8 to investigate and resolve the issue.
Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue.
Do not access or modify user data.
Avoid disrupting services or affecting system availability.
Recognition
HackerHub8 LLP appreciates responsible security research and may acknowledge researchers who responsibly report significant vulnerabilities. Recognition may include security acknowledgments or responsible researcher credits where appropriate.
Legal Safe Harbor
HackerHub8 LLP will not pursue legal action against researchers who follow this policy and conduct their research in good faith. However, malicious exploitation or misuse of vulnerabilities may result in legal consequences under applicable laws.
Policy Updates
This Vulnerability Disclosure Policy may be updated periodically to reflect evolving security practices or regulatory requirements.
Contact Information
If you have questions regarding vulnerability reporting, please contact: