************************************************************************ * SIXHACK ACADEMY - SECURITY POLICY * ************************************************************************ Last updated: July 2026 ************************************************************************ * 1. INTRODUCTION * ************************************************************************ At SixHack Academy, we take the security and privacy of our students, users and systems seriously. We welcome responsible security research and encourage researchers to report potential vulnerabilities to us privately and in accordance with this policy. This is a Vulnerability Disclosure Program (VDP). It is not a bug bounty program. ************************************************************************ * 2. CONTACT * ************************************************************************ Security reports must be sent to: info@sixhackacademy.com Please include "Security Report" in the email subject. Reports should be written in English or Spanish. ************************************************************************ * 3. AUTHORIZED SCOPE * ************************************************************************ The following assets are in scope: - sixhackacademy.com - *.sixhackacademy.com Only systems owned and directly operated by SixHack Academy are included. The presence of a SixHack Academy domain or subdomain does not automatically mean that every underlying third-party service is authorized for testing. ************************************************************************ * 4. OUT OF SCOPE * ************************************************************************ The following assets and activities are out of scope: - Third-party platforms and services. - Payment processors and financial service providers. - Email providers. - Hosting providers and infrastructure not directly managed by SixHack Academy. - Social media accounts. - Third-party integrations. - Physical security testing. - Social engineering, phishing or impersonation. - Attacks against SixHack Academy employees, students, users or suppliers. ************************************************************************ * 5. PERMITTED TESTING * ************************************************************************ Only manual, targeted, controlled and non-disruptive security testing is authorized. Researchers must: - Use their own accounts and their own data whenever authentication is required. - Make the minimum number of requests necessary to confirm a vulnerability. - Avoid accessing information belonging to other users. - Stop testing immediately if personal, confidential or third-party information is accessed. - Avoid modifying, deleting or damaging any information. - Avoid affecting the availability, stability or performance of any service. - Report vulnerabilities privately and provide enough information for SixHack Academy to reproduce and investigate the issue. - Keep all vulnerability information confidential until SixHack Academy provides written authorization for disclosure. ************************************************************************ * 6. PROHIBITED ACTIVITIES * ************************************************************************ The following activities are not authorized: - Automated vulnerability scanners. - Automated crawlers or reconnaissance tools. - Automated fuzzing. - Automated exploitation frameworks. - High-volume enumeration. - Brute-force attacks. - Credential stuffing. - Password spraying. - Denial-of-service or distributed denial-of-service testing. - Stress testing or load testing. - High-volume, parallel or repetitive requests. - Exploitation beyond what is strictly necessary to demonstrate the vulnerability. - Accessing accounts or data belonging to other users. - Downloading more data than necessary to demonstrate an issue. - Modifying, deleting, encrypting or corrupting data. - Uploading or executing malicious files. - Installing malware, shells, backdoors or persistence mechanisms. - Sending spam or unsolicited messages. - Social engineering, phishing or impersonation. - Physical security testing. - Testing third-party systems or infrastructure. - Public disclosure without prior written authorization from SixHack Academy. Intercepting proxies and other manual testing tools may be used, provided that they are operated manually and do not generate automated, high-volume or disruptive traffic. ************************************************************************ * 7. REPORT REQUIREMENTS * ************************************************************************ A useful vulnerability report should include: - The affected domain, subdomain, endpoint or URL. - A clear description of the vulnerability. - The potential security impact. - Detailed reproduction steps. - A minimal proof of concept. - Relevant HTTP requests and responses. - Screenshots, when useful. - Any prerequisites required to reproduce the issue. - Suggested remediation, when available. - The researcher's preferred name or handle for recognition. Please remove passwords, authentication tokens, personal information and any other unnecessary sensitive information from the report. Reports generated only by automated tools, without manual verification and a clear explanation of the security impact, may be closed without further investigation. ************************************************************************ * 8. DATA PROTECTION * ************************************************************************ If you accidentally access personal, confidential or third-party information: - Stop testing immediately. - Do not download, copy, store, share or modify the information. - Do not access any additional records. - Inform SixHack Academy in your report. - Securely delete any information obtained during testing after receiving confirmation from SixHack Academy. ************************************************************************ * 9. RESPONSE AND DISCLOSURE * ************************************************************************ SixHack Academy will make a reasonable effort to: - Acknowledge valid reports within five business days. - Investigate reported vulnerabilities. - Keep the researcher informed when appropriate. - Resolve confirmed vulnerabilities within a reasonable timeframe. Response and remediation times may vary depending on the severity, complexity and impact of the vulnerability. Researchers must not publicly disclose a vulnerability, proof of concept or technical details without prior written authorization from SixHack Academy. ************************************************************************ * 10. REWARDS AND RECOGNITION * ************************************************************************ This is a Vulnerability Disclosure Program, not a bug bounty program. SixHack Academy does not offer or guarantee monetary compensation, payments, prizes, gifts or other financial rewards for vulnerability reports. Valid and previously unknown vulnerabilities reported in accordance with this policy may receive public recognition in the SixHack Academy Hall of Fame. Recognition: - Is voluntary. - Requires the researcher's consent. - Is subject to validation by SixHack Academy. - May be withheld when this policy has not been followed. - Does not create any entitlement to compensation or other benefits. ************************************************************************ * 11. NON-QUALIFYING REPORTS * ************************************************************************ The following reports will generally not be considered valid security vulnerabilities unless they demonstrate a clear and meaningful impact: - Missing security headers without a demonstrated impact. - Missing cookie attributes without a practical exploit. - Self-XSS. - Clickjacking on pages without sensitive actions. - Logout CSRF. - Username or email enumeration without significant impact. - Version disclosure. - Verbose error messages without sensitive information. - Open redirects without additional security impact. - Rate-limiting observations without a practical attack scenario. - Reports based only on automated scanner output. - Issues requiring obsolete or unsupported browsers. - Theoretical issues without reproducible evidence. - Previously reported or already known vulnerabilities. - Vulnerabilities affecting only third-party systems. ************************************************************************ * 12. AUTHORIZATION * ************************************************************************ Testing is authorized only when it remains within the scope and rules described in this policy. The publication of this policy or a security.txt file does not authorize any activity outside these conditions. SixHack Academy reserves the right to update, suspend or terminate this program at any time. ************************************************************************ * 13. HALL OF FAME * ************************************************************************ Researchers who responsibly disclose valid and previously unknown vulnerabilities may be recognized at: https://sixhackacademy.com/hall-of-fame.txt ************************************************************************ * END OF POLICY * ************************************************************************