Vulnerability Disclosure Policy
Vulnerability Disclosure Policy
Security and privacy of our customers are core to how we build Hiver. This page explains our stance on security testing, and how to report a vulnerability if you find one.
Our Default Stance on Security Testing
By default, Hiver does not authorize or condone active security testing of any of our products whether public-facing or private, and regardless of whether you’re a customer, a security researcher, or anyone else. This includes automated scanning, fuzzing, penetration testing, or any deliberate attempt to find vulnerabilities.
If you want to actively test a Hiver product, you must first request authorization see section “Want to Test Our Products?” below. Testing without prior written authorization from our security team is not permitted under this policy, is not protected by our safe harbor terms, and may violate our Terms of Service.
Found Something Without Testing?
If you’ve come across a suspected vulnerability incidentally not through active testing – please report it to security@hiverhq.com right away. Include:
- What you found and where
- What you were doing when you noticed it
- Any evidence you have (screenshots, error messages, etc.)
You don’t need prior authorization to report something you found this way.
Want to Test Our Products?
If you’d like to actively test Hiver’s products including as part of security research or bug bounty participation, you must:
- Read our full Bug Bounty Program page, including scope, rules of engagement, and non-qualifying findings.
- Email security@hiverhq.com requesting authorization, before doing any testing. Tell us who you are, what you’d like to test, and confirm you’ve read and agree to the Bug Bounty Program rules.
- Wait for written confirmation from our security team. We’ll confirm scope, any test accounts/environment to use, and duration.
- Test only within what we’ve authorized, and only in line with the rules on the Bug Bounty Program page.
Any findings from authorized testing should also be reported to security@hiverhq.com, following the reporting requirements on the Bug Bounty page.
One Email, No Exceptions
security@hiverhq.com is the ONLY email Hiver Information Security monitor for security reports, disclosure discussions, and testing authorization requests.
Please do not contact Hiver employees, founders, or executives directly about a security report or a request to test – via email, LinkedIn, X/Twitter, or otherwise. These will not be reviewed, do not establish priority, and are not eligible for any recognition or reward.
Safe Harbor
Security research conducted with our prior written authorization, within the scope we’ve granted, and in accordance with the Bug Bounty Program’s rules of engagement, is authorized under this policy and we won’t pursue legal action against it.
Testing conducted without prior authorization is not covered by this safe harbor, even if the finding itself turns out to be valid and is reported responsibly afterward.
Contact
security@hiverhq.com – the only channel we monitor for security reports, disclosure, and testing authorization requests.