Skip to content

Security disclosure

If you believe you have found a security vulnerability in a Hirechain system, email security@hirechain.io. Include the affected system, steps to reproduce, and potential impact.

Scope

This policy covers Hirechain's public websites and applications. Do not test third-party services or employee accounts.

Research boundaries

To keep our users and services safe, do not:

  • intentionally access, copy, change, or share data that is not yours;
  • disrupt services, including through denial-of-service testing;
  • use social engineering, phishing, or physical attacks; or
  • test in a way that affects other users or their accounts.

If you encounter data that is not yours, stop testing and report it privately.

Good-faith research

If you act in good faith and follow this policy, Hirechain considers your research authorised and will not pursue legal action against you. Please contact us before publicly disclosing a vulnerability so we can coordinate a fix.

Rewards

Hirechain does not run a paid bug-bounty programme. Any reward is entirely discretionary, and submitting a report does not create an expectation of payment.

Reports not eligible for a discretionary reward

We will not offer a discretionary reward for reports limited to:

  • missing security headers;
  • SPF, DKIM, or DMARC configuration;
  • self-XSS;
  • clickjacking on unauthenticated pages;
  • absent rate limiting; or
  • raw scanner output without a demonstrated vulnerability.