Cueing up…

Skip to main content
Hardwave Workspace is liveHardwave Academy — join the waitlist

Reporting a security problem

Last updated: September 2026

How to report something

Mail support@hardwavestudios.com with what you found, where, and how to reproduce it. Plain text is fine. If it is serious, say so in the subject line and we will look the same day.

We do not pay for reports

There is no bug bounty programme, no discretionary fund and no goodwill payment. Hardwave Studios is a very small company with one paid plug-in, and there is no budget for this. We would rather say that up front than let anyone spend a weekend on the assumption that there is money here.

What you do get

Credit on this page, by name or handle, if you want it. A straight answer about what we found when we looked, including when the answer is that it was already fixed or that we do not consider it a vulnerability. No silence, and no form letter about a security team we do not have.

What we consider ours to fix

  • Anything on hardwavestudios.com and its subdomains that we wrote.
  • Anything in the Hardwave Suite, the plug-ins, or Workspace.
  • A published vulnerability in a dependency we use, which we patch, though finding that it exists is not a discovery about us.

What we ask of you

  • Do not run automated scanners against the live site; they cost us more in noise than they find.
  • Do not access, change or keep anyone else’s data. If you reach something that is not yours, stop there and tell us.
  • Give us a reasonable window to fix it before you publish.

Credits

Nobody listed yet. The first person who sends a report about our own code will be.