We take the security of Intercept seriously. If you believe you have found a vulnerability, please report it to us responsibly.
The following are in scope for our vulnerability disclosure programme:
intercept.hijacksecurity.com — production web applicationintercept.test.hijacksecurity.com — test environmentintercept-posture-agent)Out of scope: third-party services we depend on (report to them directly), social engineering, physical attacks, denial-of-service, and findings that require privileged access already granted to your tenant.
Hijack Security supports good-faith security research. If you make a good-faith effort to comply with this policy during your research, we will:
Good faith means: do not access, modify, or destroy data that does not belong to you; do not degrade service availability; stop and report immediately if you encounter sensitive data; and give us reasonable time to resolve the issue before public disclosure.
Send vulnerability reports to security@hijacksecurity.com. Please include:
Please do not open public GitHub issues, social media posts, or support tickets for security reports.
We are grateful to the researchers who have responsibly reported issues to us. As the programme matures we will publish acknowledgements here, with the reporter's consent.
Security reports: security@hijacksecurity.com.