Legal & compliance centre

HLD Group

Responsible disclosure

Guidelines for good-faith security research on HLD Group systems.

Last updated: 24 July 2026

Version 1.2 · Review cycle: 365 days · View all frameworks

1. Our commitment

HLD Group welcomes good-faith security research that helps protect our customers and systems. We commit to working constructively with researchers who follow this policy, to responding promptly, and to not pursuing or supporting legal action against researchers for activities conducted in accordance with it.

2. Scope

The following are in scope for testing under this policy:

  • The *.hldgroup.org properties and publicly documented APIs
  • Customer trial environments explicitly labelled for testing
  • Open-source repositories officially maintained by HLD Group

Out of scope

  • Social engineering of personnel, customers, or partners
  • Physical intrusion, and denial-of-service or resource-exhaustion attacks
  • Third-party services not operated by HLD Group
  • Automated scanning that degrades production performance or availability
  • Testing that accesses, modifies, or deletes data belonging to others

3. How to report

Send reports to security@hldgroup.org with a description of the issue, steps to reproduce, an impact assessment, and a proof of concept where available. Encrypt sensitive details with our published PGP key where possible. Please report promptly after discovery and give us a reasonable opportunity to respond before taking any further action.

4. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorised, will work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action related to your research. This safe harbour reflects the spirit of authorised security testing and does not extend to activities outside this policy or that break the law.

  • Give us reasonable time — typically 90 days — to remediate before any public disclosure
  • Do not access, modify, exfiltrate, or delete data belonging to others; use only test accounts and data
  • Stop testing and notify us immediately if you encounter personal or sensitive data
  • Stop testing when asked, and coordinate any disclosure with us

5. Our response commitments

  • Acknowledge your report within five business days
  • Provide an initial assessment and triage within ten business days
  • Keep you informed of remediation progress for valid findings
  • Coordinate public disclosure timing with you where you wish to disclose

6. Recognition

We acknowledge valid reports in our security acknowledgements where researchers consent to be named. Rewards or bounties may be offered at our discretion for significant findings; this policy does not itself create a paid bounty programme or any entitlement to payment.

Research must comply with all applicable laws, including computer misuse, privacy, and data protection law. This policy does not authorise activity that would be unlawful, and it does not grant rights over third-party systems. Nothing in this policy limits protections you may have under applicable law. Where research touches systems governed by other parties, their authorisation is also required.

For contractual attestations or audit packs, contact security@hldgroup.org.