hookay
Security

Responsible disclosure

If you've found a vulnerability in a Hookay system, we want to hear from you — confidentially, encrypted, and with a guaranteed first response within 24 hours. Good-faith security research is protected under the safe-harbor policy below.

// security@hookay.eu · PGP key · security.txt

// Fingerprint 7DB8 66A6 3060 DE37 7D24 A0AD 3728 1075 4A68 8CB1

How to report

Email security@hookay.eu. Encrypt with our PGP key if the report contains anything sensitive — the key is linked below and discoverable via WKD for security@hookay.eu. Tell us what you found, how to reproduce it, and what you think the impact is. A rough note beats a polished report that never gets sent; we will come back with questions if we need more.

Please do not open a public issue, post about it, or contact individual employees before we have replied.

What happens next

We acknowledge every report within 24 hours, including weekends. Within five working days you get an initial assessment: whether we could reproduce it, how we rate the severity, and a rough timeline.

We aim to ship a fix within 90 days and will keep you updated as it moves. If a finding affects our users, they hear it from us first and plainly — that comes before any write-up. Once a fix is out, we are happy to coordinate public disclosure with you, and to credit you by whatever name you prefer, or not at all.

Safe harbor

We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith and follows this policy. We consider such research authorized under the German Criminal Code and the EU directives that mirror it, and we will say so in writing if a third party claims otherwise.

Good faith means: you stop as soon as you have proof of the issue, you access only data that is unmistakably your own, you do not degrade the service for anyone, and you give us a reasonable chance to fix things before telling the world. If you are unsure whether something crosses a line, ask first — we would rather answer a question than argue about it afterwards.

Scope

In scope: hookay.eu and its subdomains, the Hookay iOS and Android apps, our public API, and the infrastructure that serves them.

Out of scope: denial-of-service and volumetric testing, physical attacks, social engineering of our team or our providers, spam or content-policy issues, and anything that touches other people's accounts or data. Reports produced solely by an automated scanner, without a demonstrated impact, are also out of scope.

Third-party services we merely use are not ours to authorize — report those to the provider.

Rewards

We do not run a paid bug bounty. We are pre-launch and a small team, and we would rather promise a fast, honest process than a payout table we cannot yet honor. What you get: a real answer from an engineer, credit if you want it, and a written summary of what we changed.

// This policy is also the Policy: target in our security.txt, per RFC 9116. · Security notes →