generated: '2026-07-19' method: searched source: https://www.hyperguest.com/security probe: false policy: - https://www.hyperguest.com/security contact: - security@hyperguest.com bug_bounty: false bug_bounty_note: >- HyperGuest does not operate a bug bounty program and does not offer monetary rewards for vulnerability reports. safe_harbor: true disclosure_timeline_days: 90 scope: in_scope: Any digital assets owned, operated, or maintained by HyperGuest. out_of_scope: >- Assets not owned by HyperGuest should be reported to the appropriate vendors instead. researcher_expectations: - Report discovered vulnerabilities promptly. - Limit data access to the minimum necessary for a proof-of-concept. - Cease testing immediately upon encountering PII, PHI, or credit card data. - Use only official channels to report. - Do not engage in extortion. evidence: - source: https://www.hyperguest.com/security kind: disclosure-page keywords: [responsible disclosure, safe harbor, security@hyperguest.com, 90 days]