gethacked.ai

SECURITY

How gethacked.ai handles engagements.

A short page about how we work with customer systems, what we do with what we find, and what we ask of anyone who finds something in us.

Last updated August 30, 2026

Authorized testing only

Testing is performed only on systems the client owns or is explicitly authorized to have tested.

Every engagement starts with a written agreement of scope. The agreement names what we may test, what we may not, and what counts as out-of-bounds. We do not start work until that agreement is signed.

What we collect during an engagement

To do the work, we receive what the customer chooses to share: access to systems in scope, documentation, and contact details for the people we work with. We do not collect anything outside of what the engagement requires.

How findings are handled

Findings are written for the customer first and any audience they choose second. We never publish a customer’s findings without explicit permission, and we never publish the underlying evidence at all.

Anything we write about findings in public (this website, our social channels, talks) is sanitized and labeled. A real customer never appears as a case study unless they have agreed in writing.

What we ask of anyone testing us

If you have found a security issue affecting gethacked.ai, we would like to hear about it. See our Responsible Disclosure page for the contact channel (see Responsible Disclosure below) and the kind of report that helps us respond quickly.

What this site does and does not do

  • No advertising trackers, session-replay, or fingerprinting.
  • No third-party scripts beyond fonts self-hosted via Next.js.
  • Subresource Integrity where any third-party asset is added.
  • Strict Transport Security, Content Security Policy, and standard hardening headers (see response headers).