/legal/security

Security policy

Last updated: 2026-05-03

We welcome good-faith security reports for The Hatchery. Send enough detail for us to reproduce the issue and keep testing limited to the systems listed here.

Contact

Email security@hatchery.pet. We aim to acknowledge valid reports within 72 hours.

In scope

  • The production web app at hatchery.pet.
  • The public API routes exposed by the same app.
  • The public MCP endpoint for The Hatchery.

Out of scope

  • Denial-of-service testing or traffic flooding.
  • Social engineering, phishing, or physical attacks.
  • Third-party services unless the issue is caused by our configuration.
  • Accessing, changing, or deleting data that is not yours.

Safe harbor

If you act in good faith, avoid privacy violations, and give us a reasonable window to fix the issue before public disclosure, we will not pursue action against your research.

Security policy | The Hatchery