Please report website vulnerabilities privately to info@hecavex.com. Do not send exploit details, credentials, personal data, or unpublished research through a public issue.
HECAVEX will acknowledge valid reports when practical. This policy covers the website and its deployment configuration, not third-party software except where the site integrates it unsafely.