Questo contenuto è disponibile in inglese mentre la traduzione è in revisione. · Machine translation preview
LEGAL

Security Disclosure Policy

How to report a suspected vulnerability safely and what information helps us investigate.

Last updated: 1 ottobre 2026 · Version 1.0

1. Operator and contact

HireValid is operated by Recordskeeper Inc, a Delaware C-Corp. Our business mailing address is 2261 Market Street STE 86483, San Francisco, CA 94114. Send suspected vulnerabilities to [email protected]. Include a concise summary, affected URL or component, steps to reproduce, observed impact and a safe way to contact you. Avoid sending sensitive information in an initial unencrypted message; ask for a suitable channel if needed.

2. Scope

Reports about HireValid-controlled website and service components are welcome. Third-party systems, customers’ accounts and providers’ infrastructure are not authorized testing targets under this policy. A publicly accessible endpoint does not grant permission to access private records or bypass another person’s account controls.

3. Safe investigation

Use your own accounts and the minimum interaction necessary to demonstrate the issue. Do not disrupt service, perform denial-of-service tests, persist access, deploy malware, use social engineering or access, modify or export another person’s data. If you encounter personal information, stop testing and describe its location without copying the records.

4. Handling a report

We assess scope, severity and reproducibility, may request clarification, and coordinate remediation and appropriate status updates. Response and remediation depend on the risk and complexity; this policy does not promise a fixed response SLA. Please give us a reasonable opportunity to address an issue before publishing details that could enable exploitation.

5. Researcher information and recognition

We use reporter contact details to investigate and communicate about the report and limit internal sharing to those who need it. Public credit requires your agreement. This is not a paid bounty program and does not promise a reward. Any broader testing permission or safe-harbor agreement must be provided expressly in writing.

6. Other requests

Account support, privacy requests and suspected fraudulent invitations should be sent through the relevant support or privacy channel. If you believe an active incident threatens candidate data, mark the report clearly and provide a factual description without further intrusive testing.