Trust
Responsible disclosure
Last updated 6 August 2026
We welcome reports that help keep Hansala and its customers safe. Please follow this policy so we can fix issues before they are widely known.
How to report
- Email security@hansala.com with a clear description and steps to reproduce.
- Include impact, affected URLs or endpoints, and any proof-of-concept that does not harm other customers.
- Machine-readable contact: /.well-known/security.txt
Rules of engagement
- Do not access, modify, or delete other customers' data.
- Do not disrupt availability (no DoS / load testing against production).
- Do not social-engineer Hansala staff or customers.
- Automated scanning is allowed only if it stays within normal product rate limits and does not degrade the service.
Our commitment
- We acknowledge reports as soon as practical.
- Please allow a reasonable time to investigate and remediate before public disclosure.
- We will not pursue legal action against researchers who follow this policy in good faith.
Out of scope
Issues that require physical access, outdated browsers, or speculative reports without a working path to impact are usually out of scope. Product questions belong at Contact, not this inbox.
See also Security.