Security

Report it and we will answer.

A static site with no accounts, no payments and no database has a small attack surface. If you find something anyway, here is how to tell us and what we will do about it.

Last updated 10 August 2026

What this site is

This website is a static export: plain HTML, CSS and JavaScript served as files. There is no application server, no database, no user accounts, no login, no payment processing and no personal data stored in it. The contact form composes a message and hands it to your own mail client rather than posting anywhere; where it cannot, it opens the same message in Gmail or Outlook, which is the one path that puts your text in front of a third party, and the privacy notice says so.

We say this so you can judge the risk yourself rather than take our word for it.

Reporting a vulnerability

Email hello@hyperorbits.com with "Security" in the subject. Tell us what you found, how to reproduce it, and what an attacker could do with it. A proof of concept helps.

We will acknowledge within three working days and tell you what we intend to do. If you want credit when it is fixed, say so and we will give it. If you would rather stay anonymous, that is fine too.

We have no bug bounty and no budget for one. We are not going to pretend otherwise; what we can offer is a fast, honest reply from the person who can actually fix it.

What we ask

Give us 90 days from the day you report an issue before publishing it. If we fix it sooner we will tell you and you can publish straight away. If we are going to need longer we will tell you before day 90 and say why. If we go quiet on you for 30 days, treat the 90 days as waived and publish. Do not access, alter or destroy data that is not yours, do not degrade the service for other people, and do not use social engineering or physical attacks.

In scope: hyperorbits.com, including any www form of it that resolves, and any software we have supplied you directly. Out of scope: any other hostname, including preview or staging URLs our host generates, and our hosting provider's own infrastructure. If you are unsure whether something is in scope, email us and ask before you test it. If the issue is in our host's infrastructure rather than our site, email us anyway and we will tell you who to report it to.

In return: if you stay inside this policy, we treat your testing as authorised by us for the purposes of the Computer Misuse Act 1990. We will not report you, we will not bring or support a claim against you, and we will say so in writing if you need us to. If a third party comes after you for research you did within this scope, tell us and we will confirm to them that you had our permission.

The research is in scope too

If you think a published result is wrong, that is closer to a security report than a complaint, and it is the most useful message we can receive. Ask for the seeds and the harness, try to break the claim, and tell us what you find. We would rather withdraw a result than defend it.