Security
Report a security issue.
OHIIHO welcomes coordinated disclosure of security issues affecting our public services. If you have found something, tell us.
01 · HOW TO REPORT
Contact
Email security@ohiiho.com. A machine-readable pointer is published at /.well-known/security.txt per RFC 9116.
Please include enough detail to reproduce the issue: the affected URL or service, the steps, and any supporting material.
02 · SCOPE
What this covers
This policy covers OHIIHO’s public web properties — ohiiho.com and research.ohiiho.com.
Our engagement Surfaces are designed to receive hostile interaction. Probing a HIIH Surface is expected and out of scope for this policy: those environments are built to receive it. This policy is about issues in our own public infrastructure.
03 · COORDINATED DISCLOSURE
Working together
- Give us a reasonable window to investigate and remediate before any public disclosure.
- Do not access, modify or exfiltrate data that is not yours, and do not degrade our services.
- Act in good faith and within the law. We will not pursue good-faith research conducted under these principles.
If you need an encrypted channel, say so in your first email and we will share instructions.