Skip to content

Security: HailBytes/hailbytes-api-docs

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

HailBytes takes security vulnerabilities seriously. If you discover a security issue in this repository or any HailBytes product, please do not open a public GitHub issue.

How to Report

Email: security@hailbytes.com

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested mitigations (optional)

We will acknowledge receipt within 2 business days and aim to provide a resolution timeline within 7 business days.


Supported Versions

Version Supported
Latest
N-1 ✅ Security fixes only
< N-1

Disclosure Policy

HailBytes follows a coordinated disclosure model. We ask that you:

  1. Report the vulnerability to us privately first.
  2. Give us reasonable time to investigate and patch (typically 90 days).
  3. Avoid publicly disclosing details until a fix is available.

We will credit researchers in our release notes unless you prefer to remain anonymous.


Scope

This security policy covers:

  • Code and configurations in this repository
  • HailBytes ASM and SAT APIs
  • HailBytes BYOC deployment modules

Out of scope: third-party dependencies (please report those upstream), HailBytes.com marketing website.


PGP Key

For sensitive disclosures, our security team PGP key is available at:
hailbytes.com/.well-known/security.txt

There aren't any published security advisories