The Hartwell Labs coordinated-disclosure program: security challenges across our products, safe harbor for researchers, CVE credits and a public Hall of Fame.
git clone https://github.com/Hartwell-Labs/hack-the-labEvery capability below ships in the open-source core — MIT licensed, CI on every push.
Good-faith research against in-scope products is explicitly protected — security research stays legal here.
Reports are acknowledged within 48 hours — researchers never shout into a void.
Real CVEs with real credit for real findings — your name on the advisory.
Public recognition for every accepted report, maintained in the open.
One program covering the lab's products — from the eBPF sensor to the browser OS.
Public policy, public hall, public fixes — the whole disclosure loop is auditable.