WarmHawk runs your mailbox credentials, DNS, and TLS certificates on infrastructure you own. We take reports about all of that seriously.
This file is the org-wide default (applies to any WarmHawk repo without
its own SECURITY.md). Full coordinated-disclosure policy, scope, and
safe-harbor terms: https://warmhawk.com/security
Email security@warmhawk.com with the affected component, steps to reproduce, and the impact you believe it has. Non-destructive proof-of-concept details help us triage faster. Avoid including live credentials or customer data in the report itself.
- First response within 1 business day
- 4 business hours for anything critical
We'll keep you updated as triage and a fix progress, and credit your report (if you'd like) once it's resolved.
We won't pursue legal action against good-faith researchers who test within the published scope, avoid destructive actions, and report privately before any public disclosure — see the full policy for details.