Security & Responsible Disclosure
Last updated · February 2026
We take security seriously. If you believe you've found a vulnerability, please report it privately — do not publicly disclose the details before we've had a chance to respond.
How to report
Email admin@thehexlabs.com with:
- A clear description of the vulnerability.
- Steps to reproduce.
- The impact (data exposure? account takeover? denial of service?).
- Any suggested remediation.
Please give us 90 days to fix before publishing anything about the issue.
Scope
All properties under thehexlabs.com. Excluded: third-party services (Google, OpenAI, etc.) — please report those directly to the vendor.
Out of scope
- Social engineering of our staff or users.
- Physical attacks against our facilities.
- Denial-of-service attacks that degrade the service for others.
- Reports generated purely by automated scanners with no verified impact.
Our commitments
- We acknowledge reports within 3 business days.
- We keep you updated as we investigate.
- We won't pursue legal action against researchers acting in good faith.
- We are grateful — hall-of-fame credit available on request.
Other security features
- All traffic served over TLS.
- OAuth tokens for Gmail/Calendar are encrypted at rest (Fernet AES-128-CBC + HMAC-SHA256).
- Login events include IP, browser, OS and approximate country — visible to you in MySpace.
- Admin actions are recorded in an append-only audit log.
Questions or concerns? Write to us at admin@thehexlabs.com or krajapraveen@thehexlabs.com.