🛡️ Cybersecurity Acknowledgements
Hanseong Revival Press Hall of Fame
Last updated: 4 September 2026
Scope: https://www.hanseongrevival.org/ and https://sionsavedbygrace.blogspot.com/
Our Commitment to Security
At Hanseong Revival Press, we deeply value the importance of digital security in protecting the integrity of our mission and the trust of our readers. We are committed to maintaining a secure environment, and we are grateful for the efforts of individuals who help us identify and responsibly disclose vulnerabilities.
This Hall of Fame recognises those who have contributed to strengthening the security of our Online Properties through responsible disclosure.
Scope
This policy applies to our websites:
- https://www.hanseongrevival.org/
- https://sionsavedbygrace.blogspot.com/
Our Blog is hosted on Google's Blogger platform. Vulnerabilities in the Blogger platform itself should be reported directly to Google via Google's Vulnerability Reward Programme (https://bughunters.google.com), not to us. Issues arising from our own content, configuration, or linked services remain in scope here.
This is not a bug bounty programme. No compensation, reward, or bounty is offered for reports; recognition in the Hall of Fame is the sole acknowledgement provided.
Responsible Disclosure Policy
We encourage responsible disclosure of any security vulnerability relating to our Online Properties or associated systems.
If you discover a vulnerability, we kindly ask that you:
- Report it directly to us by email:
📧 hanseongrevivalpress@protonmail.com, cc security@hanseongrevival.org - Include sufficient detail for us to understand and reproduce the issue — ideally the affected URL or system, step-by-step reproduction instructions, an impact assessment, and, where applicable, proof-of-concept material;
- Allow us a reasonable period to investigate and remediate the vulnerability before any public disclosure. Unless otherwise agreed, we ask for a coordinated disclosure window of ninety (90) days from your report, in line with common industry practice. This period may be extended by mutual agreement where a fix requires more time.
Our Commitments to You
- We will acknowledge your report within seven (7) business days of receipt;
- We will keep you reasonably informed of our progress until the issue is resolved;
- We will notify you once a fix has been deployed, and add your name to this Hall of Fame (with your permission) once the vulnerability has been remediated.
Safe Harbour
If you act in good faith, comply with this policy, and avoid privacy violations, service disruption, data exfiltration, and unauthorised access beyond what is strictly necessary to verify a vulnerability, we will not pursue legal action in respect of your responsible research.
What to Include in a Report
- A clear description of the vulnerability and its security impact;
- Step-by-step reproduction instructions;
- Proof-of-concept (screenshots, payloads, or recordings), where applicable;
- Your name and contact details, for acknowledgement and follow-up.
Out of scope: reports consisting solely of automated scanner output, theoretical findings without demonstrated impact, duplicates, best-practice recommendations, missing security headers without a demonstrated exploit path, and issues on third-party services (which should be reported to the relevant provider).
Eligibility for Recognition
To be eligible for inclusion in our Hall of Fame, submissions must:
- Represent a previously unknown and valid security issue;
- Be reported responsibly, without exploitation or unauthorised access;
- Include clear, reproducible steps or sufficient detail to verify the issue.
We reserve the right to determine eligibility and to update this policy as necessary.
Acknowledgements
We express sincere appreciation to the following individuals and researchers who have responsibly reported vulnerabilities and supported the improvement of our security:
Honourees
- No honourees listed at present. This section will be updated as new contributors are recognised.
Safe Testing Guidelines
Testing must never include: denial-of-service attempts, spam, social engineering of our personnel, testing on third-party platforms (including Google's Blogger infrastructure), or accessing, modifying, or exfiltrating data that is not your own. If you encounter personal data during testing, stop immediately and include this in your report without storing or copying the data.
Thank You
We extend our heartfelt thanks to all cybersecurity researchers and responsible members of the community who help protect Hanseong Revival Press.
Together, we can build a more secure and resilient ministry platform, to the glory of God.
🔒 "The prudent see danger and hides himself, but the simple go on and suffer for it." — Proverbs 27:12 (ESV)
Questions regarding this policy may be directed to hanseongrevivalpress@protonmail.com. This page should be read together with our Privacy Policy, Cookie Policy, and Data Protection Notice.