Security
Responsible disclosure
Found a vulnerability in Hexsting AS's systems? Thank you for letting us know. Here's how to report it and what you can expect from us.
Last updated: 2 October 2026
01How to report
- Email post@hexsting.no with “Vulnerability” in the subject line, or call +47 400 95 199.
- Describe the vulnerability, where it is and how to reproduce it.
- Don't include sensitive data you gained access to. If we need more, we'll agree on a secure channel.
02What you can expect from us
- Confirmation that we've received your report within 3 business days.
- Regular updates while we investigate and fix the issue.
- Credit once the issue is resolved, if you'd like it.
03Guidelines
- Only test systems that belong to Hexsting AS.
- Don't access, modify or delete data that isn't yours beyond what's needed to demonstrate the vulnerability.
- No denial-of-service, social engineering or physical attacks.
- Give us reasonable time to fix the issue before disclosing anything publicly.
04Safe harbour
If you act in good faith and follow the guidelines above, we will not report you to the police or take legal action against you for your research.
05Vulnerabilities found elsewhere
When we find vulnerabilities in other vendors' software during our work, we notify the vendor first and allow reasonable time for a fix before anything is made public.
06security.txt
The contact details below are also published in machine-readable form at /.well-known/security.txt. /.well-known/security.txt