Security Policy / Responsible Disclosure Policy

Last updated: 4 September 2026

We take security seriously and deeply value the contributions of security researchers and the broader security community.

The responsible disclosure of potential vulnerabilities helps us ensure the security and privacy of our users, data, and services. This Responsible Disclosure Policy outlines our expectations when security vulnerabilities are reported and provides guidelines for conducting security research in a safe and lawful manner. This policy should be read together with our Privacy Policy, Data Protection Notice, and Cybersecurity Acknowledgements (Hall of Fame) page.

1. SCOPE

This policy applies to:

All public-facing systems and services operated by Hanseong Revival Press; Our websites: https://www.hanseongrevival.org/ and https://sionsavedbygrace.blogspot.com/; Applications, content, and configurations explicitly owned or controlled by Hanseong Revival Press.

Out of scope:

The Blogger platform itself 
  • the Blog runs on Google's infrastructure; vulnerabilities in Blogger should be reported to Google via Google's Vulnerability Reward Programme https://bughunters.google.com 
  • Third-party services or products not directly controlled by us; 
  • Social engineering (e.g., phishing our personnel); 
  • Physical attacks against property or staff.
2. HOW TO REPORT

If you believe you have discovered a potential security vulnerability in any system or service operated by Hanseong Revival Press, report it to:

Email: hanseongrevivalpress @ protonmail. com Subject line: "Vulnerability Report – [brief description]"

Your report should contain sufficient detail to allow us to reproduce and evaluate the vulnerability: the affected URL or system, step-by-step reproduction instructions, an impact assessment, and, where applicable, proof-of-concept material. Do not include or retain personal data of others encountered during testing; if you encounter any, stop immediately and note it in your report without storing or copying it.

3. GUIDELINES FOR RESPONSIBLE DISCLOSURE

Researchers must:
  • Avoid violating privacy, destroying data, or interrupting our services;
  • Use only legal, non-destructive testing methods;
  • Report vulnerabilities promptly and directly through the channel above;
  • Provide sufficient information to reproduce and validate the vulnerability;
  • Allow a reasonable period for remediation before public disclosure — we ask for a coordinated disclosure window of ninety (90) days from report, extendable by mutual agreement;
  • Refrain from public disclosure before resolution, absent our express permission.
In turn, we commit to:
  • Acknowledge receipt of your report within seven (7) business days;
  • Provide status updates at least every fourteen (14) business days thereafter until resolution;
  • Work diligently to remediate verified vulnerabilities in a timely manner;
  • Credit researchers on our Hall of Fame page with their permission, once a vulnerability has been remediated.
4. SAFE HARBOUR

When conducting vulnerability research within the scope of this policy and in good faith:
  • We consider your research activities, as described in this policy, to be authorised;
  • We will not initiate legal action against you if you act in good faith and comply with this policy;
  • Should legal action be initiated against you by a third party, we will make it clear that your activities were conducted in compliance with this policy.
5. EXCLUSIONS

The following activities are prohibited and are not protected by this policy's safe harbour:
  • Denial-of-service or distributed denial-of-service attacks;
  • Physical security attacks against premises or facilities;
  • Social engineering against Hanseong Revival Press personnel;
  • Testing that results in service interruptions or damage;
  • Accessing, modifying, or exfiltrating data that is not your own;
  • Testing against third-party platforms (including Google's Blogger infrastructure — report such issues to the platform provider);
  • Persistence, lateral movement, or privilege escalation beyond what is strictly necessary to verify a vulnerability.
6. ACKNOWLEDGEMENTS AND RECOGNITION

We appreciate the efforts of security researchers who responsibly disclose vulnerabilities. With your permission, we would be honoured to recognise your contribution on our Cybersecurity Acknowledgements (Hall of Fame) page once the vulnerability has been remediated. Recognition is the sole form of acknowledgement we offer; this is not a bug bounty programme, and no monetary reward is offered.

7. UPDATES TO THIS POLICY

We may update this Responsible Disclosure Policy from time to time to reflect changes in our systems or practices. We encourage you to review it periodically. The date at the top indicates when it was last revised.

8. CONTACT

Hanseong Revival Press Email: 
Location: Kudat Division, Sabah, Malaysia (North Borneo)

This policy is provided for informational purposes and does not disclose contact info as legal advice.

نموذج الاتصال