Security disclosure
If you believe you have found a security vulnerability in a Hirechain system, email security@hirechain.io. Include the affected system, steps to reproduce, and potential impact.
Scope
This policy covers Hirechain's public websites and applications. Do not test third-party services or employee accounts.
Research boundaries
To keep our users and services safe, do not:
- intentionally access, copy, change, or share data that is not yours;
- disrupt services, including through denial-of-service testing;
- use social engineering, phishing, or physical attacks; or
- test in a way that affects other users or their accounts.
If you encounter data that is not yours, stop testing and report it privately.
Good-faith research
If you act in good faith and follow this policy, Hirechain considers your research authorised and will not pursue legal action against you. Please contact us before publicly disclosing a vulnerability so we can coordinate a fix.
Rewards
Hirechain does not run a paid bug-bounty programme. Any reward is entirely discretionary, and submitting a report does not create an expectation of payment.
Reports not eligible for a discretionary reward
We will not offer a discretionary reward for reports limited to:
- missing security headers;
- SPF, DKIM, or DMARC configuration;
- self-XSS;
- clickjacking on unauthenticated pages;
- absent rate limiting; or
- raw scanner output without a demonstrated vulnerability.