Security & responsible disclosure
If you believe you found a vulnerability in NumberHub, report it privately to [email protected]. Do not publish the issue before we have had a reasonable opportunity to investigate.
Include in your report
- Affected URL or API endpoint and the observed impact.
- Clear reproduction steps using the smallest safe test case.
- Relevant request IDs, timestamps, screenshots, or logs with secrets removed.
- A secure way to contact you for follow-up.
Testing boundaries
Use only accounts and data you control. Do not access another user’s information, disrupt service, run denial-of-service tests, send spam, or perform social engineering. Stop when you have enough evidence to describe the issue. This policy does not offer a bounty or authorize testing against upstream providers.
Our response
We will acknowledge actionable reports, investigate in good faith, and coordinate remediation and disclosure timing when appropriate. We do not pursue legal action for good-faith research that follows these boundaries.