We welcome reports of security issues in HoneySolver: the browser extension, the local engine, this website and the API.
How to report
Email security@honeybee.wtf with what you found, the steps to reproduce it, and the impact you expect. Please don't open a public issue for a vulnerability.
What to expect
- We'll acknowledge your report within 3 business days.
- We'll keep you updated while we investigate and fix it.
- With your permission, we'll credit you once the fix ships.
Safe harbor
We won't take legal action against good-faith research that follows this policy: you test only against your own accounts and data, avoid harming other users and the service, don't access more data than you need to show the issue, and give us reasonable time to fix it before disclosing it.
Out of scope
- Denial-of-service and volumetric load testing.
- Social engineering, and physical attacks.
- Findings in third-party services we use, such as hCaptcha itself.
- Missing best-practice headers with no demonstrable impact.
Our machine-readable contact details are in /.well-known/security.txt.