Haulvana takes security seriously. We welcome responsible disclosure of vulnerabilities
that help protect our systems and our customers.
Overview
This program exists to identify and resolve security issues before they can impact our platform or the operations that rely on it.
If you believe you've found a vulnerability, we want to hear from you. Reports that are clear, reproducible, and within scope will be reviewed and addressed.
Haulvana supports responsible disclosure and may offer discretionary rewards for valid findings.
Scope
✓ In Scope
•
Haulvana web application
•
Public APIs
•
Authentication and account access flows
•
Data access and multi-tenant boundaries
✗ Out of Scope
•
Third-party services or integrations
•
Social engineering attempts
•
DoS or DDoS attacks
•
Automated scanning that impacts system performance
•
Physical attacks
Submission Process
Submit all reports through the designated form below. Each report must include:
✓ A clear description of the vulnerability
✓ Step-by-step reproduction instructions
✓ Expected vs. actual behavior
✓ Impact assessment
✓ Supporting evidence (screenshots, logs, or proof of concept)
Reports that are incomplete, vague, or not reproducible will not be reviewed.
Requirements
To be eligible for review, submissions must:
✓ Describe a new, previously undisclosed vulnerability
✓ Be submitted by the original discoverer
✓ Be reproducible on production systems
✓ Avoid data exfiltration, modification, or destruction
✓ Avoid service disruption of any kind
✓ Not be publicly disclosed prior to resolution
Failure to meet these requirements will result in disqualification.
Rewards
Haulvana offers discretionary rewards for valid, high-impact vulnerability reports. Rewards are determined based on severity, exploitability, and overall impact. Not all submissions qualify for compensation.
Critical
High
Medium
Low
Informational
Reward Stacking
Rewards may be stacked for distinct, independently exploitable vulnerabilities. Stacking does not apply to:
✗ Issues stemming from the same root cause across multiple endpoints
✗ Repeated variations of the same vulnerability
✗ Vulnerabilities that must be chained to create impact
Chained exploits are rewarded based on final severity only.
Safe Harbor
Haulvana will not pursue legal action against researchers acting in good faith and in accordance with this policy. To qualify:
✓ All testing must remain within defined scope
✓ All rules and requirements must be followed
✓ No actions may impact system availability, data integrity, or user privacy
Response Expectations
• Initial response within 3–5 business days
• Triage and resolution timelines vary based on severity and complexity
Submit a Report
To report a vulnerability, use the submission form below.
For general security inquiries: