1. Our commitment
Hozit values responsible reports that help improve the security of its websites, systems and services.
Reports submitted in good faith and in accordance with this policy will be reviewed and handled responsibly.
2. How to report a vulnerability
Email security@hozit.co.za and include:
- the affected website, hostname, IP address or service;
- a clear description of the suspected vulnerability;
- steps required to reproduce the issue;
- the potential security impact;
- supporting screenshots, logs or proof-of-concept details;
- the date and time of testing; and
- your preferred contact details.
3. Testing guidelines
Researchers must:
- act in good faith;
- avoid accessing unnecessary personal or confidential information;
- stop testing when sensitive information is encountered;
- avoid changing, deleting or corrupting information;
- avoid disrupting services or degrading performance;
- avoid social engineering Hozit personnel or customers;
- avoid physical-security testing;
- avoid automated testing that creates excessive traffic; and
- allow reasonable time for investigation and remediation.
4. Prohibited activities
The following activities are not authorised:
- denial-of-service or distributed denial-of-service attacks;
- destructive testing;
- malware deployment;
- credential theft or phishing;
- extortion or threats;
- accessing customer accounts without authorisation;
- publishing confidential information;
- testing third-party systems not controlled by Hozit; and
- any activity that violates applicable law.
5. Scope
This policy applies to publicly accessible websites and services owned or directly controlled by Hozit.
Customer-owned systems, supplier platforms and third-party services are excluded unless Hozit expressly confirms otherwise.
6. What to expect
Hozit will aim to:
- acknowledge a credible report;
- review and classify the issue;
- request additional information where needed;
- coordinate remediation according to risk and feasibility;
- provide reasonable progress updates where appropriate; and
- confirm when the issue has been resolved or otherwise addressed.
Response and remediation timeframes depend on severity, complexity, operational impact and third-party dependencies.
7. Public disclosure
Researchers should not publicly disclose a suspected vulnerability before Hozit has had a reasonable opportunity to investigate and remediate it.
Any coordinated public disclosure must be agreed in writing.
8. Rewards
Hozit does not currently operate a formal paid bug-bounty programme.
Submission of a report does not create an entitlement to payment, compensation, employment or public recognition.
9. Good-faith research
Hozit will consider the nature, proportionality and good faith of the activity when assessing reports submitted under this policy.
This policy does not authorise unlawful activity, access to third-party information or conduct outside the stated guidelines.
10. Contact
Security reports should be sent to security@hozit.co.za .
General support requests should continue to use the normal Hozit support channels.