Vulnerability Disclosure Policy
Effective date: June 7, 2026
HOA in a Box welcomes reports from security researchers and the public that help us keep our website and platform secure. This policy explains how to report a vulnerability, what is in scope, and what you can expect from us. We are committed to working with good-faith researchers and will not pursue legal action against those who follow this policy.
1. How to report
Email [email protected] with a clear description of the issue, the steps to reproduce it, the affected URL or component, and any proof-of-concept material. A PGP key is available on request for encrypted reports. Please do not report security issues through public channels such as social media or public issue trackers.
2. Our commitment
- We will acknowledge receipt of your report within 2 business days.
- We will provide an initial triage assessment within 5 business days.
- We work to remediate confirmed vulnerabilities on a risk-prioritized basis, targeting: critical severity within 15 calendar days, high severity within 30 calendar days, and medium severity within 60 calendar days.
- We will keep you informed of our progress and, with your permission, credit you once the issue is resolved.
3. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activities authorized, we will not initiate or recommend legal action against you for that research, and we will not report you to law enforcement. This safe harbor does not apply to activity that intentionally harms HOA in a Box, our customers, or any individual, or that violates applicable law. If a third party initiates action against you for activity conducted in accordance with this policy, we will make this authorization known.
4. Rules of engagement
To keep research safe for everyone, you agree to:
- Avoid privacy violations, data destruction, and degradation of our services — do not run denial-of-service tests, send spam, or use automated scanning that disrupts the service;
- Access only data that belongs to you or to a test account you control; if you encounter personal data, confidential testing records, or other sensitive data, stop, do not copy or retain it, and report it immediately;
- Not exploit a vulnerability beyond the minimum necessary to demonstrate it, and not pivot to other systems;
- Keep the details of any vulnerability confidential until we confirm it has been remediated, and coordinate any public disclosure with us; and
- Comply with all applicable laws.
5. Scope
In scope: the public HOA in a Box marketing website at hoainabox.com
and the HOA in a Box platform and its public application endpoints. Out of scope:
- Third-party services and subprocessors we use (please report those to the relevant provider; see our Subprocessor List);
- Findings from automated tools without a demonstrated, exploitable impact; volumetric or denial-of-service issues; and social-engineering or physical attacks against HOA in a Box staff or facilities;
- Best-practice or informational findings without security impact (for example, missing security headers on endpoints with no sensitive functionality, or reports based solely on software-version banners).
6. What we ask in return
Give us a reasonable time to remediate before any public disclosure, and do not access, modify, or delete data that is not yours. We do not currently operate a paid bug-bounty program; recognition is offered with the reporter's permission.
7. Contact
Security reports, and abuse or acceptable-use concerns (see our Acceptable Use Policy): [email protected].
Last updated: June 7, 2026