Security

Responsible disclosure

If you believe you have found a security vulnerability in a system operated by Interview HR, please tell us privately. We value the work of security researchers and will work with you to investigate and resolve valid reports.

Last updated 16 August 2026

1. How to report

Email your report to support@interviewhr.com. Please include as much of the following as you can:

  • A clear description of the vulnerability and its impact
  • The affected URL, API, or component
  • Steps to reproduce the issue and a minimal proof of concept
  • Relevant screenshots or logs, without unnecessary personal data
  • A safe way for us to contact you with follow-up questions

Do not include secrets or personal data in the email unless they are strictly necessary to explain the issue. If sensitive evidence is required, ask us to arrange an appropriate transfer method.

2. Scope

This policy covers interviewhr.com, its subdomains, APIs, and other services operated by Interview HR. If you are unsure whether a system is in scope, contact us before testing it.

Third-party services and customer-controlled systems are outside scope. Please report vulnerabilities in those systems to their respective operators.

3. Good-faith research

When investigating, please:

  • Test only accounts and data that belong to you or that you have explicit permission to use
  • Use the minimum access necessary to demonstrate the issue
  • Stop immediately if you encounter personal data, credentials, or other confidential information
  • Do not copy, retain, alter, delete, or disclose another person's data
  • Give us reasonable time to investigate and remediate before any public disclosure
  • Comply with applicable law

We will not pursue legal action against research conducted in good faith and in accordance with this policy. If you are uncertain whether an action is permitted, ask us before proceeding.

4. Prohibited testing

  • Denial-of-service attacks, load testing, or activity that degrades availability
  • Social engineering, phishing, spam, or physical attacks
  • Brute force, credential stuffing, or high-volume authentication attempts
  • Automated scanning that generates excessive traffic
  • Installing persistence, executing destructive code, or compromising other users
  • Accessing third-party systems or going beyond what is necessary to demonstrate the vulnerability

5. What to expect from us

For a complete report, we aim to:

  • Acknowledge receipt within five business days
  • Assess the impact and share meaningful progress updates when appropriate
  • Use submitted information only to investigate and remediate the issue, communicate with you about the report, and provide recognition if you request it
  • Coordinate any public disclosure with you when appropriate
  • Credit your contribution if you want recognition and it is appropriate to do so

6. Rewards and changes

This policy is not a bug bounty programme and does not promise a payment or other reward. We may update it as our services and processes evolve; the date at the top identifies the current version.

Report a vulnerability
Responsible Disclosure – Interview HR | InterviewHR