Security Vulnerability Disclosure Policy
K6VEC Amateur Radio Group, Inc. / HamClubOnline
Last Updated: September 22, 2026
Section 1Our Commitment to Researchers
If you discover a security vulnerability in HamClubOnline and report it to us in good faith in accordance with this policy, we commit to the following:
- We will acknowledge receipt of your report within 5 business days
- We will investigate and provide an initial assessment within 15 business days
- We will keep you informed of our progress as we work toward a resolution
- We will work to remediate confirmed vulnerabilities within a reasonable timeframe appropriate to the severity of the issue
- We will not pursue legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy
- We will acknowledge your contribution in our security acknowledgments if you wish to be recognized
We ask that you give us a reasonable opportunity to remediate a reported vulnerability before any public disclosure. We consider 90 days from the date of our acknowledgment to be a reasonable standard remediation window for most issues. We will work with you on timing if special circumstances apply.
Section 2Scope
The following systems and services are within the scope of this disclosure policy:
| System | URL | Status |
|---|---|---|
| HamClubOnline application | secure.hamclubonline.com | In Scope |
| HamClubOnline marketing site | www.hamclubonline.com | In Scope |
| HamClubOnline support system | secure.hamclubonline.com/support/ | In Scope |
| HamClubOnline API | secure.hamclubonline.com/api/ | In Scope |
| Third-party services (PayPal, Square, Cloudflare, Linode, Woomaps, etc.) | Various | Out of Scope |
| Club websites that embed HamClubOnline features via iframe | Various | Out of Scope |
Vulnerabilities discovered in third-party services we use should be reported directly to those providers. If you discover a vulnerability that affects our use of a third-party service in a way that puts HamClubOnline member data at risk, please report it to us as well.
Section 3What We Are Looking For
The following types of vulnerabilities are particularly relevant to HamClubOnline and will receive priority attention:
- Authentication or session management flaws that could allow unauthorized account access
- Authorization vulnerabilities that could allow a member to access data belonging to another club or member
- SQL injection or other injection vulnerabilities
- Cross-site scripting (XSS) or cross-site request forgery (CSRF)
- Vulnerabilities that could expose member personal information, including names, addresses, phone numbers, or amateur radio license data
- Vulnerabilities that could allow unauthorized activation of SMS or voice alerting features
- Insecure direct object references that expose data across club boundaries
- Sensitive data exposure in API responses
- Security misconfigurations that could be exploited to gain unauthorized access
Section 4Out of Scope
The following are explicitly out of scope for this policy and should not be tested:
- Denial of service attacks of any kind against the platform or its infrastructure
- Physical attacks against our infrastructure or facilities
- Social engineering of K6VEC staff, volunteers, or club administrators
- Automated scanning of production systems. Use of automated security research tools is permitted only within a test environment arranged with HamClubOnline in advance. Any automated scanning that generates excessive traffic or degrades service for other users is prohibited regardless of environment
- Accessing, modifying, or deleting data belonging to any club or member other than those in a test environment arranged with HamClubOnline
- Spam or email bombing through the platform’s messaging features
- Activating SMS or voice alerting features for any purpose. These features send real messages to real people and may only be activated by authorized club coordinators for permitted purposes under the Terms of Service. They must not be triggered for any testing purpose
- Vulnerabilities requiring physical access to a user’s device
- Vulnerabilities in outdated browsers or platforms that are no longer supported
- Missing security headers that do not directly lead to a exploitable vulnerability
- Self-XSS that requires a user to attack their own browser
- Rate limiting or brute force issues that are already mitigated by our infrastructure
- Theoretical vulnerabilities without demonstrated impact
Section 5Testing Guidelines
When researching potential vulnerabilities, please:
- Do not test against production accounts or data. HamClubOnline does not permit multiple accounts per person. Do not create additional accounts for testing purposes. If you need a test environment, contact us at [email protected] before beginning any testing and we will work with you to establish appropriate testing conditions. Do not access, modify, or exfiltrate data belonging to real clubs or their members.
- Minimize your footprint. Only access the minimum data necessary to demonstrate the vulnerability. Do not perform actions that could affect availability for other users.
- Do not activate alerting features. SMS and voice alerting may only be activated by authorized club coordinators for permitted purposes under the Terms of Service. Triggering these features for any testing purpose is prohibited regardless of environment.
- Do not attempt to access club data across club boundaries. Even if a vulnerability appears to allow this, demonstrating that the vulnerability exists within your arranged test environment is sufficient.
- Stop and report if you encounter personal data. If you inadvertently access personal information belonging to other members, stop your testing immediately and report what happened to us. Do not retain, copy, or further access that data.
Section 6How to Submit a Report
Please submit vulnerability reports to us by email or through our support system. We request that you include the following information to help us investigate and reproduce the issue efficiently:
- A clear description of the vulnerability and its potential impact
- The URL, endpoint, or system component affected
- Step-by-step instructions to reproduce the vulnerability
- Any proof-of-concept code, screenshots, or supporting evidence
- Your assessment of the severity of the issue
- Whether you wish to be acknowledged in our security acknowledgments
If you believe the vulnerability involves sensitive data or requires encrypted communication, please indicate that in your initial contact and we will arrange a secure channel for the full report.
Subject line: Security Vulnerability ReportSupport system: secure.hamclubonline.com/support/
K6VEC Amateur Radio Group, Inc.
10 Sage Hill
Laguna Hills, CA 92653
United States
Section 7Disclosure Timeline
We follow a coordinated disclosure model. Our standard timeline is:
- Day 0: Researcher submits report
- Within 5 business days: We acknowledge receipt and assign an internal tracking reference
- Within 15 business days: We provide an initial assessment confirming whether the issue is a valid vulnerability and our intended approach
- Within 90 days of acknowledgment: We aim to have the vulnerability remediated or a mitigation in place
- After remediation: We coordinate with the researcher on public disclosure timing if the researcher wishes to publish
For critical vulnerabilities that pose immediate risk to member data or platform availability, we will prioritize remediation and may request an accelerated timeline. We will communicate proactively if a remediation is taking longer than anticipated and explain why.
Section 8Security Acknowledgments
We maintain appreciation for researchers who have contributed to the security of HamClubOnline through responsible disclosure. If you report a valid vulnerability and would like to be acknowledged, please let us know your preferred name or handle when you submit your report. Acknowledgment is entirely optional — researchers who prefer to remain anonymous will have their privacy respected.
8.1Safe Harbor
K6VEC Amateur Radio Group, Inc. considers security research conducted in accordance with this policy to constitute authorized activity. We will not initiate legal action against researchers who:
- Notify us promptly after discovering a vulnerability
- Make a good faith effort to avoid harm to users, club data, and platform availability
- Do not exploit the vulnerability beyond the minimum necessary to demonstrate its existence
- Do not access, retain, or disclose data belonging to other users or clubs
- Allow us a reasonable time to remediate the issue before any public disclosure
Security research conducted in accordance with this policy constitutes the “express prior written permission” referenced in the HamClubOnline Terms of Service with respect to automated access and the testing of access controls, authentication mechanisms, and technical protection measures within a test environment arranged with HamClubOnline. This authorization is limited strictly to in-scope research conducted within that test environment and does not extend to production systems or out-of-scope activities.
This safe harbor applies to research conducted in good faith under the terms of this policy. It does not extend to activities that are out of scope under this policy, including denial of service attacks, unauthorized activation of alerting features, access to other users’ data, or automated scanning of production systems. We reserve all rights with respect to activities outside the scope of this policy.
If at any point you are uncertain whether a particular action is permitted under this policy, please contact us before proceeding.
Section 9Changes to This Policy
We may update this Security Vulnerability Disclosure Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page. The most current version of this policy will always be available at this URL and is referenced in our security.txt file.