Commitment to Security

At True Hemp Science, we take the security of our website, systems, and customer data seriously. We appreciate the efforts of security researchers and the broader community in helping us maintain a safe and secure environment.


Reporting a Vulnerability

If you believe you have discovered a security vulnerability, we encourage you to report it responsibly.

Please include the following details in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any proof-of-concept (screenshots, code, etc.)

Contact Information

We will acknowledge receipt of your report as soon as possible.


Responsible Disclosure Guidelines

We ask that you:

  • Do not exploit the vulnerability beyond what is necessary to demonstrate it
  • Do not access, modify, or delete data that does not belong to you
  • Do not disrupt our services or systems
  • Give us reasonable time to investigate and resolve the issue before public disclosure

Scope

This policy applies to:

  • truehempscience.com
  • Any associated subdomains or services owned and operated by True Hemp Science

Out of Scope

The following are generally considered out of scope:

  • Social engineering attacks (phishing, impersonation, etc.)
  • Denial of service (DoS/DDoS) attacks
  • Issues requiring physical access to systems
  • Automated vulnerability scan reports without proof of exploitability

Safe Harbor

We will not take legal action against researchers who:

  • Act in good faith
  • Follow this policy
  • Do not intentionally harm our users or systems

Updates

We may update this policy from time to time. Please check this page periodically for changes.