Security evidence

Security, Audits, and Disclosure

This page distinguishes public evidence from product intent. It will not imply an audit, certification, response commitment, or bounty that has not been established.

Last reviewed: August 10, 2026

Independent audit status

BlueHammer does not currently publish a third-party no-logs, infrastructure, or application security audit report. We therefore do not describe the service as independently audited.

If a report is published, this page will identify the auditing organization, report date, product or infrastructure scope, assessed version, material limitations, and a public report link.

Report a vulnerability

Email [email protected] with the subject Security Report. Include the affected product or URL, the date observed, impact, and minimal reproduction steps. Do not access other users' data, disrupt service, or publish sensitive details before we can respond.

The first response will confirm receipt and request any missing details. This page does not promise a bounty, safe-harbor term, or response deadline that has not been formally established.

Product and privacy boundaries

A VPN changes which network party can observe a connection; it does not make a signed-in account anonymous or replace malware and phishing protection. Cleaner actions should be reviewed before removal. Store and website billing operate through different channels.

These boundaries are reflected in current product copy. Material claims that require external evidence will be linked here rather than represented by an unsupported badge.