Hiver Bug Bounty Program

Thanks for your interest in helping us keep Hiver secure. This page covers everything you need to know before you start: how to get authorized, what’s in scope, the rules of engagement, and what we don’t consider a valid finding.

 

Please read this in full before contacting us. Testing without prior authorization, or outside these rules, is not covered by our safe harbor terms — see our Vulnerability Disclosure Policy for details.

Get Authorized Before You Test

We do not allow open-ended testing of our products. Before you do anything else:

 

  1. Email security@hiverhq.com with:
    • Your name/handle and how to reach you
    • What product(s) or area(s) you’d like to test
    • Confirmation that you’ve read this page in full and agree to the rules below
  2. Wait for written confirmation from our security team before you begin. We’ll confirm the scope, any test/sandbox account you should use, and how long the authorization is valid for.
  3. If your plans change (new scope, new technique, more time needed), check back in with us authorization doesn’t automatically extend to things you didn’t originally ask about.

 

We aim to respond to authorization requests within [3-4] business days.

Rules of Engagement

Do

  • Get written authorization from security@hiverhq.com before any testing begins
  • Test only what we’ve explicitly authorized
  • Use a test account you create yourself never a real customer’s account or data, even with their informal permission
  • Stop testing and report to security@hiverhq.com immediately once you’ve confirmed a vulnerability
  • Give us a clear, reproducible proof of concept for anything you report
  • Personally verify and reproduce any finding before submitting it including anything surfaced with the help of an AI tool or scanner (see below)
  • Keep any confirmed vulnerability confidential until we’ve resolved it and agreed on disclosure timing with you
  • Delete any data you accessed or downloaded while testing, once your report is submitted

 

Don’t

  • Don’t test any Hiver product production or otherwise without prior written authorization
  • Don’t access, view, modify, download, or exfiltrate real customer data, under any circumstances
  • Don’t run automated scanners against our production environment without explicit permission as part of your authorized scope
  • Don’t perform testing that could degrade service for real users: denial-of-service, resource exhaustion, spam/flooding, or large-scale brute-force
  • Don’t attempt social engineering, phishing, or physical-access attacks against Hiver employees, contractors, or customers
  • Don’t publicly disclose, post, or discuss a vulnerability before we’ve confirmed a fix and agreed on disclosure timing
  • Don’t submit a report generated primarily by an AI tool or automated scanner without independently verifying and reproducing it yourself
  • Don’t contact Hiver employees, founders, or executives directly about testing or a report security@hiverhq.com only
  • Don’t test third-party services we integrate with (Gmail, Outlook, Slack, WhatsApp, telephony/voice providers, etc.) report issues with those directly to the vendor, unless the issue is specifically in how Hiver’s integration handles data

 

Violating these rules including testing without authorization can result in disqualification from this program and removal of safe harbor protection.

Scope

In-Scope Properties (once authorized)

  • Hiver in Gmail – our Chrome extension and its backend services (v2.hiverhq.com)
  • Hiver Omni – our standalone omnichannel web app (app.hiverhq.com)
  • hiverhq.com and its subdomains (excluding clearly third-party-hosted content such as our blog CDN, status pages, or embedded widgets)
  • developer.hiverhq.com and the Hiver API
  • Hiver AI Agents and AI Copilot, for issues that cross an actual security boundary (see below)
  • Our Help Center and Customer Portal products

 

AI Agents & Copilot – What Counts as In-Scope

Hiver’s AI Agents and Copilot take real actions on customer data. We’re interested in:

  • An AI Agent or Copilot returning, accessing, or acting on data belonging to a different customer/tenant than the one it’s serving
  • Prompt injection (via email content, attachments, or other untrusted input) that causes the agent to take an unauthorized action – sending an email, modifying a ticket, exposing another customer’s data, exfiltrating data externally with a working proof of concept
  • Any bypass of tenant isolation or permission boundaries via an AI feature

Not in scope on its own:

  • Getting a model to produce an unexpected, biased, false, or “jailbroken” text response, with no demonstrated cross-tenant access, unauthorized action, or data exposure
  • General complaints about AI output quality or accuracy

Reporting Requirements

When you submit a finding to security@hiverhq.com, include:

 

  • A clear description of the vulnerability and its impact
  • Step-by-step reproduction instructions
  • A working proof of concept (screenshots, request/response captures, or a short video)
  • The specific product/property affected
  • Confirmation that you personally reproduced and verified the finding, including if AI tools assisted your research

 

One vulnerability per report. Reports based solely on automated scanner or AI-tool output, without independent manual verification and a working PoC, will be closed without further correspondence.

Non-Qualifying Findings

Based on our current risk assessment, we don’t consider the following to be security issues on their own. This list may be updated as our products evolve.

 

  1. Missing security headers (CSP, X-Frame-Options, HSTS, etc.) without a demonstrated exploit
  2. Clickjacking on non-sensitive or marketing pages
  3. Self-XSS (requiring the victim to paste code into their own browser console)
  4. SPF, DKIM, or DMARC configuration findings for hiverhq.com or its subdomains
  5. Rate-limiting or brute-force issues on non-authentication endpoints, or without a working PoC
  6. Username/email enumeration via login, signup, or password-reset messages
  7. Descriptive error messages, stack traces, or verbose error pages that don’t expose sensitive data
  8. Software, framework, or library version/banner disclosure
  9. Missing HttpOnly or Secure flags on non-sensitive cookies
  10. Session/cookie validity after logout or password change, without a demonstrated session hijack
  11. Open redirects with no demonstrated further impact (e.g., credential or token theft)
  12. CSRF on forms with no state-changing or sensitive action, or on unauthenticated forms
  13. Content spoofing or text injection with no ability to execute code or harvest credentials
  14. Reports based solely on automated scanner or AI-tool output without independent manual verification
  15. Theoretical attack scenarios without demonstrated exploitability
  16. Denial-of-service or resource-exhaustion findings (do not test these see Rules of Engagement)
  17. Vulnerabilities in third-party services we integrate with (Gmail, Outlook, Slack, WhatsApp, telephony providers, etc.), unless specifically in how Hiver’s integration handles data
  18. Findings that require an already-compromised Google, Microsoft, or Slack account
  19. General best-practice or hardening suggestions with no demonstrated exploit path
  20. Public information disclosure via robots.txt, sitemap.xml, or other intentionally public files
  21. Directory listing on non-sensitive static asset paths
  22. Vulnerable JS libraries flagged only by version number, without demonstrated exploitability in our implementation
  23. Unminifying, reverse-engineering, or de-obfuscating client-side JS with no resulting vulnerability shown
  24. Password strength/complexity policy suggestions
  25. Missing CAPTCHA
  26. AI Agent/Copilot producing an unexpected or “jailbroken” text response with no demonstrated security impact
  27. Duplicate reports of an issue already known to us or reported by another researcher
  28. Reports submitted through any channel other than security@hiverhq.com
  29. Any finding resulting from testing that was not explicitly authorized in advance

Severity & Recognition

  • Tiered rewards: Define severity tiers (e.g., using CVSS 3.1) mapped to specific reward amounts, and only consider reports rated a set threshold (e.g., 7.0+) for reward eligibility.
  • Invite-only rewards: Hiver reserves the rights to share rewards for vetted, invite-only tier of researchers with a track record.

Our Response Process

  • Authorization requests: acknowledged within [3] business days
  • Vulnerability reports: acknowledged within [3-4] business days
  • Triage: we validate and assess severity using CVSS 3.1 as a reference
  • Updates: we’ll let you know once a fix is scheduled or shipped, and will coordinate with you on disclosure timing

Contact

security@hiverhq.com – for authorization requests, testing questions, and vulnerability reports. This is the only channel we monitor.

4.6 out of 5 star rating

based on 2,000+ reviews from

"G2, Capterra, and Chrome Web Store rating icons"
Security and compliance badges including ISO 27001 and AICPA SOC

Get Hiver's Chrome extension for Gmail to start your 7-day free trial!

Step 1

Add Hiver’s extension to your Gmail from the Chrome Webstore

Step 2

Log in to the extension to grant necessary permissions

Step 3

Enjoy your 7-day free trial of Hiver

Hiver logo

The modern AI-powered
customer service platform

Want Hiver, without the Gmail extension?

Try Hiver Omni. It runs right in your browser, with no extension to install.

gmail extension fallback
logo stripe

Thank you for your interest!

The web app is currently under development—we’ll notify you as soon as it’s live.

In the meantime, you can get started with your 7-day free trial by downloading our Gmail extension.

Hiver logo

The agentic customer
service platform

The agentic customer service platform

“Our clients choose us over competitors due to our speed and quality of communication. We couldn’t achieve this without Hiver”

"Nathan Strang of Flexport, Hiver customer"
Fin Brown

Project Manager

Getitmade@2x

Get in touch with us

Fill out the form and we’ll get back to you.

demo popup graphic

Get a personalized demo

Connect with our customer champion to explore how teams like you can leverage Hiver.

Excellent choice! 🎉 You're all set

An email with the session details is on its way to your inbox. We can’t wait to connect with you!

Meanwhile, here’s how you can learn more about Hiver:

You missed selecting
a time slot! 🗓️

No worries! You can choose a time below, and one of our experts will contact you shortly.