Hiver Bug Bounty Program
Thanks for your interest in helping us keep Hiver secure. This page covers everything you need to know before you start: how to get authorized, what’s in scope, the rules of engagement, and what we don’t consider a valid finding.
Please read this in full before contacting us. Testing without prior authorization, or outside these rules, is not covered by our safe harbor terms — see our Vulnerability Disclosure Policy for details.
Get Authorized Before You Test
We do not allow open-ended testing of our products. Before you do anything else:
- Email security@hiverhq.com with:
- Your name/handle and how to reach you
- What product(s) or area(s) you’d like to test
- Confirmation that you’ve read this page in full and agree to the rules below
- Wait for written confirmation from our security team before you begin. We’ll confirm the scope, any test/sandbox account you should use, and how long the authorization is valid for.
- If your plans change (new scope, new technique, more time needed), check back in with us authorization doesn’t automatically extend to things you didn’t originally ask about.
We aim to respond to authorization requests within [3-4] business days.
Rules of Engagement
Do
- Get written authorization from security@hiverhq.com before any testing begins
- Test only what we’ve explicitly authorized
- Use a test account you create yourself never a real customer’s account or data, even with their informal permission
- Stop testing and report to security@hiverhq.com immediately once you’ve confirmed a vulnerability
- Give us a clear, reproducible proof of concept for anything you report
- Personally verify and reproduce any finding before submitting it including anything surfaced with the help of an AI tool or scanner (see below)
- Keep any confirmed vulnerability confidential until we’ve resolved it and agreed on disclosure timing with you
- Delete any data you accessed or downloaded while testing, once your report is submitted
Don’t
- Don’t test any Hiver product production or otherwise without prior written authorization
- Don’t access, view, modify, download, or exfiltrate real customer data, under any circumstances
- Don’t run automated scanners against our production environment without explicit permission as part of your authorized scope
- Don’t perform testing that could degrade service for real users: denial-of-service, resource exhaustion, spam/flooding, or large-scale brute-force
- Don’t attempt social engineering, phishing, or physical-access attacks against Hiver employees, contractors, or customers
- Don’t publicly disclose, post, or discuss a vulnerability before we’ve confirmed a fix and agreed on disclosure timing
- Don’t submit a report generated primarily by an AI tool or automated scanner without independently verifying and reproducing it yourself
- Don’t contact Hiver employees, founders, or executives directly about testing or a report security@hiverhq.com only
- Don’t test third-party services we integrate with (Gmail, Outlook, Slack, WhatsApp, telephony/voice providers, etc.) report issues with those directly to the vendor, unless the issue is specifically in how Hiver’s integration handles data
Violating these rules including testing without authorization can result in disqualification from this program and removal of safe harbor protection.
Scope
In-Scope Properties (once authorized)
- Hiver in Gmail – our Chrome extension and its backend services (v2.hiverhq.com)
- Hiver Omni – our standalone omnichannel web app (app.hiverhq.com)
- hiverhq.com and its subdomains (excluding clearly third-party-hosted content such as our blog CDN, status pages, or embedded widgets)
- developer.hiverhq.com and the Hiver API
- Hiver AI Agents and AI Copilot, for issues that cross an actual security boundary (see below)
- Our Help Center and Customer Portal products
AI Agents & Copilot – What Counts as In-Scope
Hiver’s AI Agents and Copilot take real actions on customer data. We’re interested in:
- An AI Agent or Copilot returning, accessing, or acting on data belonging to a different customer/tenant than the one it’s serving
- Prompt injection (via email content, attachments, or other untrusted input) that causes the agent to take an unauthorized action – sending an email, modifying a ticket, exposing another customer’s data, exfiltrating data externally with a working proof of concept
- Any bypass of tenant isolation or permission boundaries via an AI feature
Not in scope on its own:
- Getting a model to produce an unexpected, biased, false, or “jailbroken” text response, with no demonstrated cross-tenant access, unauthorized action, or data exposure
- General complaints about AI output quality or accuracy
Reporting Requirements
When you submit a finding to security@hiverhq.com, include:
- A clear description of the vulnerability and its impact
- Step-by-step reproduction instructions
- A working proof of concept (screenshots, request/response captures, or a short video)
- The specific product/property affected
- Confirmation that you personally reproduced and verified the finding, including if AI tools assisted your research
One vulnerability per report. Reports based solely on automated scanner or AI-tool output, without independent manual verification and a working PoC, will be closed without further correspondence.
Non-Qualifying Findings
Based on our current risk assessment, we don’t consider the following to be security issues on their own. This list may be updated as our products evolve.
- Missing security headers (CSP, X-Frame-Options, HSTS, etc.) without a demonstrated exploit
- Clickjacking on non-sensitive or marketing pages
- Self-XSS (requiring the victim to paste code into their own browser console)
- SPF, DKIM, or DMARC configuration findings for hiverhq.com or its subdomains
- Rate-limiting or brute-force issues on non-authentication endpoints, or without a working PoC
- Username/email enumeration via login, signup, or password-reset messages
- Descriptive error messages, stack traces, or verbose error pages that don’t expose sensitive data
- Software, framework, or library version/banner disclosure
- Missing HttpOnly or Secure flags on non-sensitive cookies
- Session/cookie validity after logout or password change, without a demonstrated session hijack
- Open redirects with no demonstrated further impact (e.g., credential or token theft)
- CSRF on forms with no state-changing or sensitive action, or on unauthenticated forms
- Content spoofing or text injection with no ability to execute code or harvest credentials
- Reports based solely on automated scanner or AI-tool output without independent manual verification
- Theoretical attack scenarios without demonstrated exploitability
- Denial-of-service or resource-exhaustion findings (do not test these see Rules of Engagement)
- Vulnerabilities in third-party services we integrate with (Gmail, Outlook, Slack, WhatsApp, telephony providers, etc.), unless specifically in how Hiver’s integration handles data
- Findings that require an already-compromised Google, Microsoft, or Slack account
- General best-practice or hardening suggestions with no demonstrated exploit path
- Public information disclosure via robots.txt, sitemap.xml, or other intentionally public files
- Directory listing on non-sensitive static asset paths
- Vulnerable JS libraries flagged only by version number, without demonstrated exploitability in our implementation
- Unminifying, reverse-engineering, or de-obfuscating client-side JS with no resulting vulnerability shown
- Password strength/complexity policy suggestions
- Missing CAPTCHA
- AI Agent/Copilot producing an unexpected or “jailbroken” text response with no demonstrated security impact
- Duplicate reports of an issue already known to us or reported by another researcher
- Reports submitted through any channel other than security@hiverhq.com
- Any finding resulting from testing that was not explicitly authorized in advance
Severity & Recognition
- Tiered rewards: Define severity tiers (e.g., using CVSS 3.1) mapped to specific reward amounts, and only consider reports rated a set threshold (e.g., 7.0+) for reward eligibility.
- Invite-only rewards: Hiver reserves the rights to share rewards for vetted, invite-only tier of researchers with a track record.
Our Response Process
- Authorization requests: acknowledged within [3] business days
- Vulnerability reports: acknowledged within [3-4] business days
- Triage: we validate and assess severity using CVSS 3.1 as a reference
- Updates: we’ll let you know once a fix is scheduled or shipped, and will coordinate with you on disclosure timing
Contact
security@hiverhq.com – for authorization requests, testing questions, and vulnerability reports. This is the only channel we monitor.