§Trust
Report a security issue
How to tell us about a vulnerability, what is in scope, and what to expect.
Draft. This page is waiting for founder and legal review and is not yet in effect. Items marked TODO or Legal review are unresolved.
How to report
Email hello@usehorme.com with "Security" in the subject line. Please include:
- what you found and where
- steps to reproduce it
- what an attacker could do with it
- how you would like to be credited, if at all
Please do not share the issue publicly until we have had a chance to look at it and fix it.
In scope
- The Horme website at www.usehorme.com
- The Horme web app and its APIs
- The Horme runner
Out of scope
- Denial of service or load testing
- Social engineering or phishing of Horme users or anyone working on Horme
- Physical attacks
- Vulnerabilities in third party products, such as Claude Code, Codex, Supabase, or Vercel. Please report those to the company that makes them.
- Reports that only list missing best practices without a way to exploit them
While testing
- Use only accounts and runners you own.
- Do not access, change, or delete other users' data. If you reach it by accident, stop and tell us.
- Do not degrade the service for others.
- Do not run destructive tests.
TODO: safe harbour wording for good faith research, after legal review Legal review
What to expect
We read every report. We will reply once we have reviewed it and let you know what we plan to do. Horme is a small team, so we do not promise a fixed response time.
Horme does not run a bug bounty program and does not pay for reports.
Machine readable contact
Our security contact is also published at /.well-known/security.txt.
Horme