Security Policy

We take the security of our website seriously. If you've found a vulnerability, we want to hear from you.

Our commitment

H3 Marketing (operated by Housty Designs) is committed to ensuring the security of our website and the data entrusted to us. We welcome responsible disclosure from security researchers and the broader community. If you discover a vulnerability, please report it to us and we will work to resolve it promptly.

Scope

In scope

  • h3.houstydesigns.com and all subdomains
  • The contact form and any other public-facing input surfaces
  • Client-side JavaScript served from our domain
  • HTTP response headers and cookie configuration

Out of scope

  • Social engineering or phishing attacks targeting our staff
  • Physical security of our premises or hardware
  • Denial-of-service or automated high-volume scanning
  • Vulnerabilities in third-party services we use (SendGrid, Google Maps, Sentry)
  • Issues in browsers or operating systems

How to report

Send your report by email to h3@houstydesigns.com with the subject line Security Vulnerability Report. Please include:

  • A clear description of the vulnerability and where it exists
  • Step-by-step instructions to reproduce the issue
  • The potential impact if exploited
  • Screenshots, HTTP requests/responses, or a proof-of-concept (no live exploitation)

Please do not include real user data in your report. If you have inadvertently accessed personal data, let us know and delete it immediately.

What to expect

Within 48 hours
We will acknowledge receipt of your report
Within 7 days
We will confirm whether the issue is valid and provide an initial assessment
Within 30 days
Resolution target for critical and high severity issues
Within 90 days
Resolution target for moderate and low severity issues

Safe harbour

We will not pursue legal action against researchers who discover and report security vulnerabilities in good faith, provided that you:

  • Do not access, modify, or delete data that does not belong to you
  • Do not disrupt or degrade our services
  • Do not share details of the vulnerability with others before we have resolved it
  • Act in good faith and with the intent to improve security

We will not refer policy-compliant reporters to law enforcement.

Recognition

We appreciate the time and effort security researchers invest in keeping the web safer. If you report a valid vulnerability, we will acknowledge your contribution by name (or anonymously, if you prefer) in our private acknowledgements record.

Last updated: July 2026