Security Disclosure Policy
HUSH welcomes responsible disclosure from security researchers. If you believe you have found a vulnerability, we ask that you report it privately so we can investigate and fix it before details become public.
Scope
- The HUSH web app and PWA
- HUSH backend APIs and edge functions
- Authentication, encryption, ratchet, and key-management subsystems
- Calling (WebRTC), push notifications, and attachment storage
Out of scope
- Social engineering of HUSH staff or users
- Physical attacks against HUSH infrastructure
- Denial-of-service testing against production
- Automated scanner output without a working proof of concept
How to report
Email security@hushdigital.org.uk with a clear description, reproduction steps, affected components, and any proof-of-concept material. Please do not exploit the issue beyond what is necessary to confirm it, and do not access, modify, or destroy other users' data.
Our commitment
- Acknowledge your report within 3 business days.
- Provide an initial assessment within 10 business days.
- Keep you informed as we investigate and remediate.
- Credit you in our security acknowledgements unless you prefer to remain anonymous.
Safe harbour
Good-faith security research conducted in line with this policy will not result in legal action from HUSH. We treat researchers as partners, not adversaries.