Vulnerability Disclosure Policy
Last updated: 11 August 2026
We welcome reports of security vulnerabilities in Hexense HR. If you believe you have found one, please tell us at security@hexense-hr.com. We would rather hear from you than read about it later.
1. Scope
In scope:
- The Hexense HR application and its API, on any domain we operate.
- Our public surfaces: organization careers pages, the anonymous whistleblowing channel, and the sign-in and invitation flows.
Out of scope:
- Denial-of-service, volumetric, or resource-exhaustion testing of any kind.
- Social engineering of our staff or our customers, and physical attacks.
- Findings against our vendors’ own infrastructure — report those to the vendor. Our vendors are listed on our subprocessors page.
- Reports produced solely by an automated scanner, with no demonstrated impact; and issues whose only impact is a missing hardening header, a weak cipher suite with no exploit path, or a version banner.
2. How to report
Email security@hexense-hr.com with enough detail for us to reproduce the issue: the affected URL or endpoint, the steps, and what an attacker gains. A short proof of concept helps more than a long description. Please write in English or French.
3. What we ask of you
- Use only accounts and organizations you own or have permission to test. Never access, modify, or retain another organization’s data — if you can demonstrate cross-tenant access, stop at the demonstration and tell us.
- Do not run tests that degrade the service for others, and do not exfiltrate data beyond the minimum needed to prove the finding.
- Give us reasonable time to fix the issue before disclosing it publicly. We suggest 90 days from our acknowledgement, and we are happy to agree a different timeline with you.
4. What we commit to
- We acknowledge your report within 5 business days.
- We give you our assessment — whether we consider it a vulnerability, and our intended fix — within 10 business days of acknowledgement.
- We keep you updated while we work on a fix, and we tell you when it ships.
- We will credit you by name or handle when we publish the fix, if you want the credit and the report was made in good faith. Tell us how you would like to be named.
- If a vulnerability affected our customers’ personal data, our breach-notification obligations under our Data Processing Agreement apply independently of this policy.
5. Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorised, we will not pursue or support legal action against you for it, and we will say so if a third party brings action against you over research conducted within this policy. This does not extend to testing that goes beyond the scope above, and we cannot waive the rights of third parties.
6. No bug bounty
We do not currently operate a paid bug bounty programme and we do not offer payment for reports. We would rather say so plainly than leave the question open.
7. This policy in machine-readable form
The contact details above are also published at /.well-known/security.txt, per RFC 9116.