Reporting a Security Vulnerability
If you believe you have identified a security vulnerability affecting GPUHub, please report it to: support@gpuhub.com Please include as much relevant information as possible so that our technical team can reproduce and evaluate the issue. A useful report should include:- A description of the vulnerability
- The affected URL, API endpoint, service, or component
- Steps required to reproduce the issue
- The potential security impact
- Screenshots, logs, request/response examples, or other supporting evidence where applicable
- Any conditions required to reproduce the vulnerability
- Your contact information for follow-up
Responsible Testing
Security research must be conducted in a manner that does not compromise the security, privacy, availability, or integrity of GPUHub, our infrastructure, or our users. When investigating a potential vulnerability, please:- Use your own GPUHub account and resources whenever possible.
- Limit testing to the minimum necessary to demonstrate the vulnerability.
- Stop testing once sufficient evidence has been collected to demonstrate the issue.
- Avoid accessing, modifying, downloading, or deleting data belonging to other users.
- Avoid actions that could degrade or interrupt GPUHub services.
- Report the vulnerability to us promptly after confirming it.
Prohibited Activities
The following activities are not permitted without prior written authorization from GPUHub:- Denial-of-service (DoS/DDoS) testing or other availability attacks
- Stress testing or intentionally generating excessive traffic
- Destructive testing
- Social engineering, phishing, or impersonation
- Testing against GPUHub employees, customers, suppliers, or partners
- Accessing or attempting to access another user’s account
- Accessing, modifying, downloading, or deleting another user’s data
- Credential stuffing or brute-force attacks
- Large-scale automated vulnerability scanning
- Introducing malware, cryptominers, ransomware, or other malicious software
- Attempting to maintain persistent unauthorized access
- Physical attacks against GPUHub infrastructure or facilities
- Testing third-party services or infrastructure that are not operated by GPUHub
- Public disclosure of an unresolved vulnerability before GPUHub has had a reasonable opportunity to investigate and address it
Production Environment
GPUHub is a live GPU cloud platform used by customers for production workloads. Security research must therefore be conducted carefully and must not interfere with running GPU instances, network services, storage systems, APIs, payment systems, or other customers’ workloads. Please do not attempt to demonstrate the severity of a vulnerability by disrupting production services. A clear reproduction procedure or limited proof of concept is generally sufficient for our team to investigate an issue.Bug Bounty and Monetary Rewards
GPUHub currently does not operate a public bug bounty program. Submitting a vulnerability report does not create any contractual obligation for GPUHub to provide payment, compensation, rewards, employment, or other benefits. GPUHub may, at its sole discretion, choose to recognize particularly valuable security contributions. Any such recognition is voluntary and should not be interpreted as establishing a bug bounty program or an expectation of payment for future reports. Please do not conduct additional or more intrusive testing based on the expectation of receiving a reward.Security Testing Services
Submission of a vulnerability report should not be interpreted as authorization to provide penetration testing, security auditing, vulnerability scanning, or other professional services to GPUHub. GPUHub does not accept unsolicited security testing services through the vulnerability reporting process. Any formal penetration testing or security assessment must be separately authorized in writing by GPUHub.Duplicate, Informational, and Low-Impact Reports
We appreciate all good-faith reports, but we may not individually respond to reports that are duplicate, purely informational, or do not represent a meaningful security risk. Examples may include:- Missing security headers without demonstrated security impact
- Version disclosure without a demonstrated vulnerability
- Publicly available information
- Self-XSS requiring the user to execute code themselves
- Issues requiring unrealistic or highly unlikely user interaction
- Reports generated solely by automated vulnerability scanners without verification
- Rate-limit observations without demonstrated security impact
- Best-practice recommendations without an exploitable vulnerability
- Vulnerabilities affecting unsupported browsers, software, or third-party systems outside GPUHub’s control
Third-Party Services
GPUHub uses third-party services and infrastructure as part of operating our platform. Vulnerabilities that exclusively affect a third-party product or service should generally be reported directly to the relevant provider. If you believe a third-party vulnerability creates a specific security risk for GPUHub or GPUHub users, you may still notify us so that we can evaluate the potential impact.Handling of Vulnerability Reports
After receiving a security report, GPUHub may:- Review and validate the reported issue.
- Request additional information where necessary.
- Assess the potential impact and severity.
- Develop and deploy appropriate mitigations or fixes.
- Contact the reporter if further clarification is required.