Hexense HR

Vulnerability Disclosure Policy

Last updated: 11 August 2026

We welcome reports of security vulnerabilities in Hexense HR. If you believe you have found one, please tell us at security@hexense-hr.com. We would rather hear from you than read about it later.

1. Scope

In scope:

Out of scope:

2. How to report

Email security@hexense-hr.com with enough detail for us to reproduce the issue: the affected URL or endpoint, the steps, and what an attacker gains. A short proof of concept helps more than a long description. Please write in English or French.

3. What we ask of you

4. What we commit to

5. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorised, we will not pursue or support legal action against you for it, and we will say so if a third party brings action against you over research conducted within this policy. This does not extend to testing that goes beyond the scope above, and we cannot waive the rights of third parties.

6. No bug bounty

We do not currently operate a paid bug bounty programme and we do not offer payment for reports. We would rather say so plainly than leave the question open.

7. This policy in machine-readable form

The contact details above are also published at /.well-known/security.txt, per RFC 9116.