Security Notice and Responsible Vulnerability Disclosure
LAST UPDATED: JANUARY 14, 2026Document status and internal alignment
This notice describes how Hireeo receives and handles security vulnerability reports and what reporters can expect. It reflects Hireeo's current security practices and will be updated as our security program evolves.
1. How to report a vulnerability
If you find a security vulnerability, email us at security@hireeo.app describing the vulnerability, the steps to reproduce it, and its potential impact. Please give us the opportunity to investigate and remediate the issue before disclosing it publicly.
1.1. Report information
When reporting, please include:
- A description of the vulnerability and reproduction steps.
- Potential impact, including which data or functions could be affected.
- If possible, a non-destructive proof of concept.
2. What NOT to do while investigating
- Do not access, modify, or delete other users’ data.
- Do not perform tests that could degrade service for other users; do not conduct denial-of-service attacks.
- Do not publicly disclose the vulnerability before Hireeo confirms remediation or before an agreed reasonable period has elapsed.
2.1. Coordinated disclosure period
We ask for a 90-day coordinated-disclosure period before you publicly disclose any vulnerability, counted from your initial report. If we remediate the vulnerability before that period ends, we will confirm this to you so you can disclose it in coordination with us.
3. Hireeo commitment
We confirm receipt of every security report within 3 business days and provide an initial assessment within 10 business days. We do not currently offer monetary rewards (a bug bounty), but we publicly acknowledge —with your permission— researchers who responsibly report valid vulnerabilities.
3.1. Proposed response
At a minimum, the process should:
- Confirm receipt of the report.
- Inform the reporter when it has been fixed or why it is not considered a vulnerability.
- Not take legal action against a researcher who reports in good faith and follows the rules in section 2.
4. Relationship with the internal incident playbook
This public notice is the visible face of the process. Internal handling, including triage, containment, and notification to authorities where applicable, is governed by `security/incident-response-legal-playbook.md` and the breach-notification obligations in `privacy/breach-notification-protocol.md`; they are not repeated here.
5.1. Reporting channel before publication
Hireeo's responsible-disclosure program covers the Hireeo website and administration panel. Out of scope are denial-of-service attacks, social engineering against employees or users, and testing against third-party accounts without their authorization. Reports are received at security@hireeo.app.
5.2. Coordinated-disclosure period
We commit to working with you during the 90-day coordinated-disclosure period to remediate the vulnerability and keep you informed of progress. Please do not disclose the vulnerability to third parties during that period without our prior agreement.
5.3. Internal policy alignment
This policy is kept aligned with Hireeo's internal incident-response practices and is reviewed periodically. We will publish any relevant updates to the report intake and handling process here.
6. Local legal review
If you act in good faith, comply with this policy, and do not access or disclose third-party data beyond what is strictly necessary to demonstrate the vulnerability, Hireeo will not initiate legal action against you for your security research.
7. Personal data rights
You can exercise your personal data rights by writing to legal@hireeo.app. Available rights and response deadlines vary by state —including California's CCPA/CPRA and other state privacy laws—; there is no single federal data-protection authority.
8. Cooling-off or withdrawal rights when applicable (B2C)
There is no general federal cooling-off right for these transactions. State-specific rules or rules for particular transactions may apply, and mandatory applicable law will govern.
9. Dispute resolution
This notice is governed by applicable United States law. Any dispute will be resolved through binding individual arbitration under the Federal Arbitration Act (FAA), and you waive any right to participate in a class action, to the extent permitted by applicable law.
10. Contact
legal@hireeo.app
Publication status
This notice is effective as of the last updated date shown above and applies across all countries where Hireeo operates. We will publish any future changes here together with their effective date.
Thank you for helping us keep Hireeo safe.

