These public terms provide HaxLink’s standard framework. A signed master agreement, Order, statement of work, data processing agreement, or mandatory law prevails where it expressly differs.
1. Emergencies and immediate danger
If someone is in immediate physical danger, contact local emergency services first. HaxLink is not an emergency-dispatch service.
Law-enforcement and emergency preservation requests should identify the agency, officer, official contact channel, legal authority, affected resource, relevant time period, and urgency. Send them to contact@haxlink.com with “URGENT LEGAL REQUEST” in the subject.
2. What you can report
- Phishing, credential theft, impersonation, fraud, scams, or deceptive sites.
- Malware, ransomware, botnets, command-and-control, exploitation, or unauthorized access.
- Spam, unsolicited bulk messaging, open relays, or abusive automated traffic.
- Denial-of-service attacks, scanning, routing abuse, spoofing, or network disruption.
- Child sexual abuse material, non-consensual intimate imagery, credible threats, or unlawful exploitation.
- Copyright, trademark, counterfeit, privacy, doxxing, or other rights violations.
- A security vulnerability in a HaxLink-owned website, portal, API, or control-plane component.
- Any other apparent breach of the Acceptable Use Policy.
3. How to submit a useful report
Email contact@haxlink.com with the subject “Abuse Report” and the category. Clear, technically specific reports can be handled faster.
- Your name, organization, reliable contact details, and relationship to the affected system.
- Affected IP address, URL, hostname, account, or other resource identifier.
- UTC timestamps, including time zone and the duration or frequency of activity.
- A concise description of what occurred, why it is harmful or unlawful, and requested action.
- Relevant full email headers, log excerpts, packet captures, screenshots, transaction identifiers, or complaint references.
- For legal-rights complaints, the right involved, proof of authority, exact location, and applicable jurisdiction.
- Steps already taken and whether the activity remains active.
Do not send passwords, private keys, full payment-card numbers, malware executables, or unrelated personal data. Ask us for a secure transfer method if sensitive evidence is necessary.
4. Child safety reports
Do not download, copy, or redistribute suspected child sexual abuse material to document a report. Provide the exact URL or resource, observation time, and context without attaching illegal imagery.
HaxLink may immediately restrict access, preserve required information, and refer apparent child exploitation to competent authorities or recognized reporting bodies where required or appropriate.
5. Good-faith security research
If you believe you found a vulnerability in a HaxLink-owned system, report it before public disclosure. HaxLink will not pursue a claim against good-faith research that avoids privacy harm, service disruption, social engineering, physical access, extortion, persistence, and access beyond what is necessary to demonstrate the issue.
This statement applies only to systems HaxLink owns or expressly identifies as in scope. It does not authorize testing of Customer workloads, partner systems, denial-of-service activity, automated high-volume scanning, data destruction, or violation of law.
- Include reproducible steps, affected endpoint, impact, prerequisite access, and a proof of concept that minimizes data exposure.
- Stop testing and report promptly if you encounter personal data, credentials, or a path to material harm.
- Allow reasonable time for investigation and remediation before disclosure.
- Do not demand payment or threaten disclosure. No bounty is promised unless HaxLink has separately agreed in writing.
6. What happens after a report
HaxLink will triage the report, correlate it with service and partner records, assess credibility and urgency, and route it to the responsible operator. We may ask for clarification or secure evidence transfer.
Possible actions include notifying the Customer, requiring remediation, blocking traffic, quarantining or suspending resources, preserving evidence, coordinating with a partner, or referring the matter to authorities. We aim to use the least disruptive effective action consistent with safety, law, and network integrity.
We may not be able to disclose investigation details, Customer identity, or enforcement outcome because of privacy, security, legal, or contractual restrictions. An acknowledgement does not confirm that the reported resource belongs to HaxLink or that a violation occurred.
7. Triage priority
- Critical: immediate risk to life, active child exploitation, destructive compromise, active ransomware, or large-scale ongoing attack.
- High: active phishing, malware distribution, account takeover, significant data exposure, or material service abuse.
- Normal: spam, historical events, limited policy violations, rights complaints, or reports requiring more evidence.
- Low: incomplete reports, informational concerns, or issues outside HaxLink control that require referral.
8. Evidence preservation and legal requests
HaxLink may preserve relevant records when it has a reasonable basis to anticipate legal process, an active security investigation, or a serious policy violation. Preservation does not guarantee that particular data exists or can lawfully be disclosed.
Requests for Customer data must follow applicable law and legal process. HaxLink may notify the Customer unless prohibited or where notice would create a material risk.
9. Customer response and appeal
A Customer receiving an abuse notice should acknowledge it promptly, preserve relevant evidence, stop ongoing harm, investigate root cause, and provide a remediation summary. HaxLink may require credential rotation, patching, reimaging, configuration changes, or a prevention plan before restoring Service.
Customers may appeal an enforcement action by sending new technical or legal evidence to contact@haxlink.com. Restoration remains subject to risk, law, partner constraints, and the Agreement.
10. False or abusive reports
Do not submit knowingly false, misleading, harassing, duplicative, or automated complaints. HaxLink may disregard abusive submissions and may take action where a report itself violates law or another person's rights.
Contact HaxLink Limited
Include your organization, account or Order reference, and enough context for us to route your request.