Y Combinator Security and Reporting Security Issues
Y Combinator considers the security of our systems and applications to be of the utmost importance.
For security issues with Hacker News, please visit https://news.ycombinator.com/security.html.
Reporting Security Vulnerabilities
Y Combinator welcomes input from the security research community. Through responsible disclosure we hope to improve the security of our applications and user data. To that end, we encourage security researchers to notify us of any potential vulnerabilities uncovered to security@ycombinator.com.
Reports received through this channel should receive a prompt reply. If you do not receive a timely response, please attempt to contact us again.
To protect our users, we request that you refrain from sharing information about any potential vulnerabilities with anyone outside of YC. Once we have confirmed the vulnerability and mitigation, we hope that you will join us in an announcement.
Exclusions
While researching, please refrain from:
- Denial of service
- Spamming
- Social engineering (including phishing) of Y Combinator staff or contractors
- Any physical attempts against Y Combinator property or data centers
Bug Bounties
We pay bug bounties at our discretion for significant vulnerabilities responsibly disclosed.
