Security research
Responsible Disclosure
How to report a suspected vulnerability safely and what researchers can expect from HireEGG.
- Applies to
- Security researchers, customers, users, and partners.
- Effective
- July 17, 2026
- Document
- Operational policy · 2026.07
Browse all policies
01
Report privately
Send a concise report to info@hireegg.com with the subject "Security report". Do not include passwords, tokens, full candidate records, or exploit data beyond what is necessary to explain the issue.
02
What to include
- Affected product, route, feature, or API and the date observed.
- Clear reproduction steps and the expected versus observed result.
- Potential impact and the minimum evidence needed to demonstrate it.
- A safe contact method and whether you plan to publish the research.
03
Rules of engagement
- Use accounts and data you own or have explicit permission to test.
- Stop if you encounter another person's data and report the exposure without copying, changing, or retaining it.
- Do not use denial of service, spam, social engineering, physical attacks, malware, destructive testing, or automated traffic that harms availability.
- Do not access more data than needed to show the issue, establish persistence, or demand payment as a condition of disclosure.
- Give HireEGG a reasonable opportunity to investigate and fix a confirmed issue before public disclosure.
04
What HireEGG will do
HireEGG will acknowledge a useful report when reasonably possible, triage it by severity and reproducibility, ask focused follow-up questions, and share material remediation progress where appropriate. Timelines depend on impact, complexity, provider coordination, and release risk.
05
No bounty or blanket authorization
HireEGG does not currently promise a bug bounty, reward, public credit, or legal safe harbour. This policy does not authorize activity that violates law, third-party rights, contracts, or the rules above. Good-faith, careful reporting will be considered when HireEGG evaluates the matter.
Questions about this document?
Enterprise customers can also request a signed DPA, security review, or procurement materials.