Source ↗
Challenges program

hack-the-lab.
Break our products before someone else does.

The Hartwell Labs coordinated-disclosure program: security challenges across our products, safe harbor for researchers, CVE credits and a public Hall of Fame.

Coordinated disclosureSafe harborCVE creditsHall of Fame
View source ↗ Releases Full catalog
git clone https://github.com/Hartwell-Labs/hack-the-lab

Engineering, not promises.

Every capability below ships in the open-source core — MIT licensed, CI on every push.

Safe harbor

Good-faith research against in-scope products is explicitly protected — security research stays legal here.

48-hour acknowledgement

Reports are acknowledged within 48 hours — researchers never shout into a void.

CVE credits

Real CVEs with real credit for real findings — your name on the advisory.

Hall of Fame

Public recognition for every accepted report, maintained in the open.

Multi-product scope

One program covering the lab's products — from the eBPF sensor to the browser OS.

Open process

Public policy, public hall, public fixes — the whole disclosure loop is auditable.