/legal/security
Security policy
Last updated: 2026-05-03
We welcome good-faith security reports for The Hatchery. Send enough detail for us to reproduce the issue and keep testing limited to the systems listed here.
Contact
Email security@hatchery.pet. We aim to acknowledge valid reports within 72 hours.
In scope
- The production web app at hatchery.pet.
- The public API routes exposed by the same app.
- The public MCP endpoint for The Hatchery.
Out of scope
- Denial-of-service testing or traffic flooding.
- Social engineering, phishing, or physical attacks.
- Third-party services unless the issue is caused by our configuration.
- Accessing, changing, or deleting data that is not yours.
Safe harbor
If you act in good faith, avoid privacy violations, and give us a reasonable window to fix the issue before public disclosure, we will not pursue action against your research.