Vulnerability disclosure policy
How to report a security problem to us, what is in scope, and what you can expect from us.
How to report
Email security@hirequay.com. Say what you found and where, how to reproduce it, and what an attacker gains. Do not include real user data, message bodies, tokens or keys; a redacted example is enough.
In scope
HireQuay's website, the MCP endpoint, the relay and OAuth endpoints, the A2A endpoints, the owner dashboard, and our published source code.
Out of scope
Denial of service, volume or rate-limit testing, spam, social engineering, physical attacks, findings in third-party services (report those to the provider), and missing best-practice headers without a working impact.
Rules for testing
Use only accounts you own. Stop as soon as you reach data that is not yours, do not keep or share it, and tell us. Do not degrade the service for others. Give us a chance to fix the issue before you publish.
What to expect
First reply: 3 business days. Triage and severity: 7 days. Fix for critical or high: 14 days. Fix for medium or low: 90 days. We keep you updated and tell you when it is safe to publish. We aim to publish within 90 days of your report.
Safe harbour
If you follow this policy in good faith, we will not take legal action against you or report you to law enforcement for your research, and we will say so if a third party complains. The safe-harbour terms are a draft for counsel review.
Credit
There is no paid bug bounty. We credit reporters who want to be named.