How to report
Email public@thehwbco.com with the subject “Confidential security report”. Include the affected page or service, description, steps to reproduce, date and time, and the least sensitive evidence needed.
Please protect people and data
Do not access, download, alter or retain more information than necessary. Do not disclose the issue publicly while it is being assessed. Do not use denial-of-service testing, social engineering, phishing, physical intrusion, malware, high-volume scanning or attempts against accounts you do not own.
What not to send initially
Do not email passwords, recovery links, secret keys, complete CV records or unnecessary personal information. Describe sensitive evidence first so a safer transfer method can be agreed.
What you can expect
We will aim to acknowledge a credible report promptly, assess severity, involve the relevant provider where needed and keep the reporter updated when practical. We do not currently operate a paid bug-bounty programme or promise a fixed remediation time.
Scope
The public website and The Hwb Collective-controlled CV Builder are in scope. Third-party platforms should normally be reported through the provider’s own process unless the issue arises from our configuration or use.
Other concerns
A suspected personal-data breach can also be reported to privacy@thehwbco.com. Safeguarding concerns must use safeguarding@thehwbco.com; call 999 where somebody is in immediate danger.