Security Policy & Disclosure Program
We welcome reports from security researchers and the public about potential vulnerabilities in The HITS App and our infrastructure. This page describes scope, how to report, our commitments, and the safe-harbor terms under which good-faith research is authorised.
1. How to report
Email security@thehitsapp.info. Encrypt sensitive details if needed — public PGP key on request. Include:
- A clear description of the issue and its impact.
- Step-by-step reproduction instructions or a proof-of-concept.
- The URL, IP, endpoint or build version affected.
- Your contact info (email or handle for credit, if you want).
Machine-readable contact details are available at /.well-known/security.txt per RFC 9116.
2. Scope
The following systems are in scope:
- Apex marketing site —
thehitsapp.infoand all subdomains ofthehitsapp.info. - Admin dashboard —
admin.thehitsapp.info. - API —
api.thehitsapp.infoand any documented API endpoints. - Authentication —
auth.thehitsapp.infoand the OAuth/OIDC flows it implements. - Native apps — The HITS App for iOS and Android, all production builds.
3. Out of scope
- Denial-of-service (DoS / DDoS), volumetric load testing, or any test that degrades service for other users.
- Social engineering of RingTime employees, contractors, vendors or HITS staff.
- Physical attacks on offices, data centers or staff.
- Issues that require physical access to a victim's device.
- Vulnerabilities in third-party services we use (report those to the third party).
- Reports based solely on automated scanner output without a demonstrated impact.
- Missing security headers / cookie flags / SPF / DMARC findings without a demonstrated exploit.
- Self-XSS, clickjacking on pages without sensitive actions, login/logout CSRF on non-sensitive endpoints.
- Outdated TLS configuration where modern clients are unaffected.
4. Safe harbor
When research is performed in good faith and in line with this policy, RingTime will:
- Consider the research as authorised under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), and applicable equivalents.
- Not pursue or support legal action against you.
- Work with you to understand and remediate the issue.
Good-faith research means:
- Avoiding privacy violations — do not access, modify, exfiltrate or destroy data that does not belong to you. Use test accounts wherever possible.
- Stopping immediately if you discover personal data, and reporting it.
- Reporting promptly and giving us reasonable time to remediate before disclosure.
- Operating only against the in-scope systems above.
- Complying with all applicable laws.
5. Our commitments & SLAs
| Severity | Acknowledge | Triage complete | Target fix |
|---|---|---|---|
| Critical | Within 72 hours | Within 7 days | 30 days |
| High | Within 72 hours | Within 7 days | 60 days |
| Medium | Within 72 hours | Within 14 days | 90 days |
| Low | Within 72 hours | Within 30 days | Best-effort |
We will keep you informed of progress and will credit you publicly (with your permission) once the issue is fixed.
6. Rewards
We do not currently operate a paid bug-bounty program. We may, at our discretion, offer swag or recognition for impactful reports. A formal bounty program is under consideration; status will be posted here.
7. Coordinated disclosure
Please do not publicly disclose any vulnerability until we have confirmed remediation, or until 90 days have passed from your report — whichever is sooner. If you believe we are not engaging in good faith, contact legal@thehitsapp.info.