Security contact channel
Report potential vulnerabilities, suspicious logins, or credential risks
Please email support@hexvm.com, with a subject beginning “Security report.” Include the issue type, discovery time, affected functionality, minimum reproduction steps, observed result, and a preferred secure contact time.
Evidence may include sanitized request snippets, error messages, hashes, or screenshots with sensitive fields hidden. Do not send real private keys, passwords, complete access tokens, signing certificate private keys, or directly usable session data. If you suspect that credentials for an existing node are at risk, update them first, then submit a ticket for the linked order in the console.
Include
Time, impact scope, reproduction conditions, sanitized evidence
Do not include
Private keys, passwords, complete tokens, usable session data