Responsible disclosure

Report a security issue to H-One.

If you believe you have identified a security vulnerability affecting an H-One-owned system, please report it privately so it can be reviewed.

How to report

Email info@h-one.work with the subject “Responsible disclosure.” Include the affected asset, steps to reproduce, potential impact, and any supporting evidence.

Research expectations

Do not access, alter, retain, or disclose data belonging to other people. Avoid disruption, denial of service, social engineering, and testing against third-party services. Allow reasonable time for review before public disclosure.

Scope note

This page applies only to systems owned and operated by H-One. It does not authorize testing of clients, partners, providers, or unrelated third parties.