Security Disclosure Policy

HUSH welcomes responsible disclosure from security researchers. If you believe you have found a vulnerability, we ask that you report it privately so we can investigate and fix it before details become public.

Scope

  • The HUSH web app and PWA
  • HUSH backend APIs and edge functions
  • Authentication, encryption, ratchet, and key-management subsystems
  • Calling (WebRTC), push notifications, and attachment storage

Out of scope

  • Social engineering of HUSH staff or users
  • Physical attacks against HUSH infrastructure
  • Denial-of-service testing against production
  • Automated scanner output without a working proof of concept

How to report

Email security@hushdigital.org.uk with a clear description, reproduction steps, affected components, and any proof-of-concept material. Please do not exploit the issue beyond what is necessary to confirm it, and do not access, modify, or destroy other users' data.

Our commitment

  • Acknowledge your report within 3 business days.
  • Provide an initial assessment within 10 business days.
  • Keep you informed as we investigate and remediate.
  • Credit you in our security acknowledgements unless you prefer to remain anonymous.

Safe harbour

Good-faith security research conducted in line with this policy will not result in legal action from HUSH. We treat researchers as partners, not adversaries.

Last updated: June 2026. HUSH may update these policies; material changes will be announced in-app.