Document libraryکتابخانه‌ی اسناد

Reporting a security problemگزارش ایراد امنیتی

How someone who finds a security problem tells us.اگر کسی ایراد امنیتی پیدا کرد، چطور به ما خبر دهد.Vulnerability Disclosure Policy

Draft — not final. Do not publish until our lawyer approves it.پیش‌نویس است و هنوز نهایی نیست؛ تا تأیید وکیل منتشر نشود.

It still has 25 gaps, shown in yellowهنوز ۲۵ جای خالی دارد که زرد نشان داده شده [OPEN: …] · What to fill inچه چیزی پر شود

The text below is in English — the official text.متن زیر انگلیسی است؛ متن رسمی همین است.
Technical detailsجزئیات فنی
draftپیش‌نویس
IDشناسهPOL-VDP-001
Versionنسخه0.3
OwnerمسئولCTO (named person TBD) with Legal Lead
Counsel reviewبررسی وکیلnone
Next reviewبررسی بعدی2026-10-09
Fileفایلknowledge-base/05-Policies-Public/drafts/POL-VDP-001_VULNERABILITY_DISCLOSURE_POLICY_v0.3-draft.md

Vulnerability Disclosure Policy — draft

Prepared for review by licensed counsel. Not legal advice. Part B is the proposed public text; Parts A and C are internal.

Part A — Drafting brief (internal)

ItemValue
Question presentedHow can security researchers report vulnerabilities, what may they test, and what assurance can HidzoVPN lawfully give them?
DriversEU Cyber Resilience Act: Art. 14 reporting of actively exploited vulnerabilities and severe incidents — reported to apply from 11 Sep 2026; Art. 13 and Annex I Part II (vulnerability handling, coordinated disclosure policy) — reported to apply from 11 Dec 2027 (EV-224, Reported); RFC 9116 security.txt (EV-231, Reported); RSK-041; BRF-2026-001 P1-9
ModelCISA VDP template (Reported, EV-237) — written for federal agencies; adapted here into conditional, contractual commitments a private company can keep
Prerequisitessecurity@ mailbox with a named owner and backup; triage and a procedure to identify "actively exploited" vulnerabilities within CRA time limits; /.well-known/security.txt; PGP key and replies issued under the role identity "HidzoVPN Security Team" with no personal names (RSK-031) [ENGINEERING]
No rewardsNo bounty program; a later decision (roadmap #30)

Part B — Proposed public text

Vulnerability Disclosure Policy

Version: 1.0 [OPEN] · Effective: [OPEN: date]

HidzoVPN, Inc. accepts reports of security vulnerabilities in our Services. This policy explains how to report a vulnerability, what testing we authorize and what commitments we make. It supplements our Terms of Service. We do not pay rewards for reports.

1. How to report

Email [OPEN: [email protected]] [OPEN: with our PGP key at https://hidzovpn.com/.well-known/pgp-key.txt]. Please include the affected app, version, website or server; a description of the vulnerability and its possible impact; the steps needed to reproduce it; and how we can contact you. Our contact details are also published in https://hidzovpn.com/.well-known/security.txt [ENGINEERING: file live — RFC 9116].

2. What we will do

  • We will acknowledge your report within [OPEN: 3] business days [ENGINEERING: owner named; rota in place].
  • We will tell you at least every [OPEN] days whether the issue is still open [ENGINEERING].
  • We will tell you when the vulnerability has been fixed [ENGINEERING].
  • If you wish, we will credit you publicly once the issue is fixed.

3. Scope

In scope: the HidzoVPN iOS app from the App Store; the HidzoVPN Android app from Google Play or our website; the domains listed here [OPEN: list]; and our VPN servers when you connect to them as an ordinary user of your own account.

Out of scope: services, networks, hypervisors and facilities run by third parties, including Apple, Google, our payment processor and our hosting providers; physical attacks; social engineering of our staff or users; denial-of-service testing; and reports produced only by automated scanners without a demonstrated impact.

4. Rules for testing

When you test, you must:

  • use only accounts you own or have been given permission to use;
  • not intercept, collect, record or analyze the traffic, tunnel addresses or sessions of any other user;
  • not access, change or delete data belonging to other users — if you reach such data, stop, do not copy, keep or disclose it, delete any copy after you report it, and report it to us;
  • not degrade the Services for other users;
  • not use a vulnerability beyond what is needed to show that it exists;
  • not demand payment in return for not disclosing a vulnerability; and
  • keep the details confidential until the earlier of [OPEN: 30] days after we release a fix and [OPEN: 90] days after your report, unless we agree another date in writing.

Nothing in this policy prevents you from reporting a vulnerability to a national computer security incident response team (CSIRT), ENISA or another competent authority.

5. Our commitments to you

[COUNSEL: scope and wording — CFAA-aware counsel]

If you comply with this policy:

  • we will not bring a civil claim against you under the U.S. Computer Fraud and Abuse Act, state computer-crime laws, 17 U.S.C. §1201 or our Terms of Service for research that complies with this policy;
  • for that research, we waive the restrictions in Section 6.2 of our Terms of Service and items 6, 7 and 13 of Section 1 of our Acceptable Use Policy; and
  • we will not report that research to law-enforcement authorities as a crime.

These commitments do not apply if you access, keep or disclose other users' data beyond what Section 4 allows, demand payment, disrupt the Services, or disclose before the date in Section 4. They do not limit any notification the law requires us to make about a vulnerability, an incident or a personal-data breach. They bind only HidzoVPN, Inc.; they do not bind any government authority or any other person, and they cannot authorize testing of systems that others own or operate. Our authorization does not cover the laws of the country where you, or the server you test, are located.

If a vulnerability is being actively exploited, the law may require us to notify the competent CSIRT and ENISA and to inform users. We will not name you in those notices unless the law requires it or you agree [COUNSEL]. We may be unable to engage with, credit or reward people who are located in sanctioned countries or appear on sanctions lists [COUNSEL: OFAC]. We process your contact details as described in our Privacy Policy [OPEN: link; confirm the Privacy Policy covers researcher data].

7. Changes

We may update this policy. We will publish the new version with its effective date. Questions: [OPEN: [email protected]].

Part C — Drafting notes (internal)

C.1 Sources

ElementBasisLabel
Reporting of actively exploited vulnerabilities and severe incidents (applies now)Regulation (EU) 2024/2847 Art. 14; Art. 71(2)Reported (EV-224) [VERIFY]
Single point of contact; coordinated disclosure policy; user information (from 11 Dec 2027)Regulation (EU) 2024/2847 Art. 13(17); Annex I Part II points 5–6; Annex IIReported [VERIFY: Art. 71(2)]
Voluntary reporting by researchersRegulation (EU) 2024/2847 Art. 15[VERIFY]
security.txtRFC 9116Reported (EV-231)
Safe-harbour modelCISA BOD 20-01 and VDP templateVerified (B) (EV-243) — written for federal agencies; adapted because agency text is unsuitable for a private company's contractual promise
Industry standard (not law)ISO/IEC 29147:2018 (Edition 2; revision under development)Verified (B) (EV-242)
DOJ charging policy for good-faith researchJustice Manual 9-48.000 (updated May 2022): prosecutors "should decline" good-faith security research; creates no enforceable rights — so the VDP must not suggest DOJ protectionVerified (B), archived official copy; live page not reachable (EV-238)
Anti-circumvention exemption37 C.F.R. §201.40(b)(18) (89 FR 85446, 28 Oct 2024) — expressly "not a safe harbor from, or defense to" other laws incl. the CFAA; 17 U.S.C. §1201(j) requires the owner's authorisation; re-check after the tenth triennial rule (expected Oct 2027)§201.40 Verified (A) (EV-239, EV-240); §1201(j) Reported (mirror, EV-241)
InterceptionWiretap Act, 18 U.S.C. §2511[VERIFY]
Sanctions (import of services from Iran)31 C.F.R. §560.201[VERIFY]; [COUNSEL: OFAC]

C.2 Conforming edits required

ToS §6.2 and AUP §1 add "except as permitted by our Vulnerability Disclosure Policy". Privacy Policy covers researcher correspondence.

C.3 Limits of this analysis

(a) Not reviewed: Florida Computer Abuse and Data Recovery Act and ch. 815; UK Computer Misuse Act 1990; EU member-state criminal law; GDPR for researcher data. (b) Not opened: CRA text (EUR-Lex); DOJ Justice Manual; §1201 exemption. (c) Facts unknown: mailbox, owner, asset list, server countries (RSK-030), hosting-contract holders (RSK-036). (d) Counsel required: CFAA-aware security counsel; OFAC; EU counsel (CRA).

C.4 Review log

DateReviewerVerdictNotes
2026-09-25Drafted—v0.1
2026-09-25hidzo-counsel-reviewer (AI)REVISE (9 Majors)v0.2: conditional safe harbour with defeating conditions and waiver of ToS/AUP restrictions; no interception of other users; hosts out of scope; CRA timing split; right to report to CSIRT/ENISA; sanctions and privacy notice; bracketed service commitments; data-handling duty; embargo tied to fix release; role identity for PGP and replies
2026-09-25hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235REVISE (set: 1 Blocker, 8 Majors)v0.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264)