Legal

Security Policy

How to report a security concern about this website, and what we ask of anyone who looks.

Last updated: October 7, 2026

1. Reporting a concern

If you believe you have found a security problem on hutchinsdatastrategy.com, email chris@hutchinsdatastrategy.com with the subject line "Security report".

A report we can act on includes:

  • The exact page, URL, or endpoint affected
  • Step-by-step instructions to reproduce the problem
  • What you believe the impact is
  • Evidence, such as a screenshot, a request and response, or a short recording

A message that says a problem exists but gives none of these details is not something we can verify or fix. Please send the details in your first message.

2. No bug bounty

Hutchins Data Strategy does not run a bug bounty program and does not pay for vulnerability reports, solicited or unsolicited. Please do not send a report on the condition that we agree to pay for it. We will not agree to any payment before seeing a report, and we will not respond to requests for one.

3. What we ask of you

This site is a public marketing site. Reading its public pages as a visitor is welcome. Beyond that, we have not authorized testing of our systems. In particular, please do not:

  • Run automated scanners, crawlers, or fuzzers against the site or its forms
  • Send high volumes of requests or anything that could degrade the site for other visitors
  • Try to access, change, or delete data that is not yours
  • Use phishing, social engineering, or any contact with our team or clients to gain access
  • Test the third-party services the site relies on. Those belong to their owners, and we cannot authorize testing of them

If you come across personal information by accident, stop, do not keep or share it, and tell us.

4. Reports we generally cannot act on

  • Output from an automated scanner with no demonstrated impact
  • Missing or unusual security headers with no working exploit
  • Email configuration findings without proof that mail can be spoofed in practice
  • Issues that need physical access to a device or an already compromised browser
  • Reports about content or services we do not control

5. What happens next

We read reports that include the details above. We may reply to ask for more information. We may not reply to messages that do not follow this policy. Where a report is valid, we fix the problem and may thank you by name if you ask us to.

6. Legal notice

This page describes how to contact us. It is not a license to test our systems, and it does not waive any right or remedy available to Hutchins Data Strategy under the law.

7. Other inquiries

For anything that is not a security report, such as a speaking request or a consulting inquiry, please use the contact page.