Legal

Responsible Disclosure Policy

Last updated: 2026-08-07

Reporting a security issue

We take the security of candidate and customer data seriously. If you believe you have found a security vulnerability in Hirevoice, we want to hear from you.

Email: security@hirevoice.com

Please include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, and what you observed. A proof of concept, screenshots or a short recording help us act faster. If you would like to encrypt your report, say so and we will arrange a secure channel.

What you can expect from us

  • Acknowledgement within 3 working days that we have received your report.
  • An initial assessment within 10 working days, telling you whether we have reproduced the issue and how we have rated its severity.
  • Progress updates while we work on a fix, and confirmation when it is deployed.
  • Credit, if you would like it. Tell us how you wish to be named; we are happy to acknowledge researchers publicly once an issue is resolved.

We do not currently operate a paid bug bounty programme. Reports are welcomed on their merits.

What we ask of you

  • Give us reasonable time to fix the issue before disclosing it publicly. We aim to resolve confirmed issues promptly and will agree a disclosure timeline with you.
  • Do not access, modify, or delete data that is not yours. If a vulnerability exposes another person's data, stop, record only what is needed to demonstrate the issue, and tell us.
  • Do not degrade our service. No denial-of-service testing, no automated scanning that generates significant load, no spam or social engineering of our staff, customers or candidates.
  • Do not use physical attacks against our offices or personnel.
  • Comply with applicable law. Nothing in this policy authorises activity that is unlawful.

Scope

In scope

  • hirevoice.com and its subdomains
  • hirevoice.ai and its subdomains
  • The Hirevoice web applications: recruiter dashboard, candidate interview experience, and the public API

Out of scope

  • Third-party services we use but do not operate (report those to the provider directly)
  • Findings that require physical access to a user's unlocked device
  • Social engineering, phishing of staff, and physical security testing
  • Reports produced solely by automated scanners without a demonstrated, exploitable impact
  • Missing security headers, cookie flags, or TLS configuration details with no demonstrated exploit path
  • Rate-limiting or brute-force concerns without a working demonstration
  • Vulnerabilities in third-party libraries with no demonstrated exploit path in our product

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised, will not pursue or support legal action against you in relation to it, and will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised.

If you are unsure whether something is in scope or whether a particular test is acceptable, ask us first at security@hirevoice.com.