Security and vulnerability disclosure
If you find a security problem in Mosshatch or hatchkind.com, please tell us. We would rather hear about it from you than from anyone else.
How to report
- Email security@mosshatch.com. Our security.txt lists the same contact.
- Say what you found, where, and the steps to reproduce it. A short proof of concept helps.
- We acknowledge within two business days and tell you what we will do within ten.
In scope
- mosshatch.com and its API under /api/.
- hatchkind.com.
- The mosshatch command-line tool and the MCP server.
Out of scope
- Denial of service, load testing and spam.
- Social engineering of our staff, our providers or our customers, and physical attacks.
- The services of our providers (the registrar partner, Stripe, Vercel, Neon, Resend, AWS). Report those to them.
- Reports from automated scanners without a demonstrated impact.
Please
- Test only against accounts and domains you own, or that the owner has allowed you to use.
- Stop as soon as you reach data that is not yours. Do not keep, share or change it, and tell us what you saw.
- Never try to reveal a secret stored in someone else's Nest.
- Give us 90 days to fix a problem before you publish, or tell us why you need less.
Safe harbor
If you act in good faith and follow this policy, we will consider your research authorised, we will not pursue or support legal action against you for it, and we will say so if a third party brings a claim against you over it. If you are unsure whether something is allowed, ask us first at the address above.
This safe harbor covers only our own systems and our own claims. It cannot bind our providers or anyone else.
Thanks
We will credit you when we publish a fix, if you want us to. We do not run a paid bug bounty yet.