Security

Report a security issue.

OHIIHO welcomes coordinated disclosure of security issues affecting our public services. If you have found something, tell us.

01 · HOW TO REPORT

Contact

Email security@ohiiho.com. A machine-readable pointer is published at /.well-known/security.txt per RFC 9116.

Please include enough detail to reproduce the issue: the affected URL or service, the steps, and any supporting material.

02 · SCOPE

What this covers

This policy covers OHIIHO’s public web properties — ohiiho.com and research.ohiiho.com.

Our engagement Surfaces are designed to receive hostile interaction. Probing a HIIH Surface is expected and out of scope for this policy: those environments are built to receive it. This policy is about issues in our own public infrastructure.
03 · COORDINATED DISCLOSURE

Working together

  • Give us a reasonable window to investigate and remediate before any public disclosure.
  • Do not access, modify or exfiltrate data that is not yours, and do not degrade our services.
  • Act in good faith and within the law. We will not pursue good-faith research conducted under these principles.

If you need an encrypted channel, say so in your first email and we will share instructions.