Hoslift legal
Security and Responsible Disclosure
The terms and information that apply to this part of Hoslift.
Last Updated: 1 August 2026
Purpose
Hoslift values good-faith security research and welcomes responsible reports that help protect its public Website, visitors and systems. This Policy explains what may be tested, how to report a suspected vulnerability and the conditions that apply to authorized research.
In-Scope Assets
The following assets are in scope:
- the production Website at https://hoslift.com;
- pages, forms, APIs and static assets served from that production origin; and
- any additional Hoslift-controlled asset that Hoslift expressly confirms in writing is in scope.
Only security vulnerabilities in Hoslift-controlled code or configuration are covered. If a vulnerability appears to affect an underlying third-party service, report it to Hoslift without testing the provider beyond what is necessary to demonstrate the impact on the in-scope Website.
Out-of-Scope Activity and Findings
The following are not authorized:
- testing client systems, LakCloud infrastructure, third-party platforms or any asset not listed above;
- accessing, changing or deleting another person's data;
- phishing, impersonation, social engineering, spam or physical-security testing;
- denial-of-service, load testing, automated traffic likely to impair service, or resource exhaustion;
- malware, persistence, destructive actions, data exfiltration or attempts to obtain secrets beyond the minimum proof required;
- testing that violates law, contractual restrictions or a third party's rights;
- public disclosure before coordinated resolution; and
- reports limited to missing best-practice headers, version banners, clickjacking on pages with no sensitive action, self-XSS, speculative issues without demonstrated impact, or automated scanner output without validation.
Safe Research Rules
To remain within this Policy:
- use only accounts, systems and data that you own or have written permission to use;
- make a reasonable effort to avoid privacy violations, service degradation and disruption;
- use the minimum interaction and evidence necessary to confirm the issue;
- stop immediately if you encounter personal data, credentials, secrets or the ability to cause material harm;
- do not retain, copy or share unnecessary data;
- securely delete retained evidence after the report is resolved or when Hoslift asks you to do so; and
- allow Hoslift a reasonable opportunity to investigate and remediate before any disclosure.
This Policy does not grant access to systems or data beyond the scope above.
How to Report
Send reports to hello@hoslift.com with the subject Security Report, or use the Contact page and select or state that the message concerns security.
Include, where available:
- the affected URL or asset;
- a clear description of the vulnerability and potential impact;
- reproducible steps or a minimal proof of concept;
- relevant request and response details with secrets removed;
- the date and time of testing; and
- a safe way to contact you.
Do not send live credentials, private keys, unnecessary personal data or destructive proof. If sensitive evidence cannot be sent safely by ordinary email, first request a secure transfer method.
Current machine-readable reporting details are published at https://hoslift.com/.well-known/security.txt.
Response and Coordination
Hoslift aims to:
- acknowledge a report within 3 business days;
- provide an initial triage update within 10 business days;
- communicate material status changes while remediation is in progress; and
- coordinate reasonable disclosure timing after remediation.
These are targets, not guarantees or contractual service levels. Resolution time depends on severity, complexity, third-party dependencies and the availability of a safe fix. Duplicate, out-of-scope or non-actionable reports may receive a brief response without further updates.
Good-Faith Commitment
If you make a reasonable, good-faith effort to follow this Policy and applicable law, Hoslift will not initiate legal action solely because of that authorized research. If accidental access occurs, stop, do not retain or disclose the data, and report the event promptly.
This commitment does not authorize unlawful conduct, waive the rights of affected third parties, bind third parties or prevent Hoslift from acting against conduct that is malicious, reckless, deceptive, disruptive or outside this Policy.
Disclosure, Credit and Rewards
Do not publicly disclose a vulnerability or identifying details until Hoslift confirms remediation or agrees to a disclosure date. Hoslift may limit disclosure where details would create continuing risk, expose personal data or harm another party.
Reporter credit may be provided by mutual agreement. Hoslift does not currently operate a bug-bounty programme and does not promise payment, rewards or compensation unless separately agreed in writing before the relevant work.
Policy Changes
Hoslift may update this Policy as its Website, reporting channels and security programme develop. The version and last-reviewed date above identify the current publication.