Security & Responsible Disclosure

Last updated · February 2026

We take security seriously. If you believe you've found a vulnerability, please report it privately — do not publicly disclose the details before we've had a chance to respond.

How to report

Email admin@thehexlabs.com with:

  • A clear description of the vulnerability.
  • Steps to reproduce.
  • The impact (data exposure? account takeover? denial of service?).
  • Any suggested remediation.

Please give us 90 days to fix before publishing anything about the issue.

Scope

All properties under thehexlabs.com. Excluded: third-party services (Google, OpenAI, etc.) — please report those directly to the vendor.

Out of scope

  • Social engineering of our staff or users.
  • Physical attacks against our facilities.
  • Denial-of-service attacks that degrade the service for others.
  • Reports generated purely by automated scanners with no verified impact.

Our commitments

  • We acknowledge reports within 3 business days.
  • We keep you updated as we investigate.
  • We won't pursue legal action against researchers acting in good faith.
  • We are grateful — hall-of-fame credit available on request.

Other security features

  • All traffic served over TLS.
  • OAuth tokens for Gmail/Calendar are encrypted at rest (Fernet AES-128-CBC + HMAC-SHA256).
  • Login events include IP, browser, OS and approximate country — visible to you in MySpace.
  • Admin actions are recorded in an append-only audit log.
Questions or concerns? Write to us at admin@thehexlabs.com or krajapraveen@thehexlabs.com.