HomeVulnerability Disclosure Policy

Vulnerability Disclosure Policy

Hirance is committed to keeping our platform secure. We welcome responsible security research and appreciate your help in protecting our users.

Hirance Private LimitedLast updated: March 2026

Hirance Private Limited ("Hirance") takes the security of its platform, mobile application, and user data extremely seriously. If you have discovered a security vulnerability in any of our systems, we encourage you to disclose it to us responsibly through this policy.

Scope

This policy applies to security vulnerabilities discovered in Hirance's digital assets including:

  • hirance.com and all subdomains
  • The Hirance mobile application (Android)
  • Hirance backend APIs and infrastructure
  • Employer and candidate portals

How to Report a Vulnerability

Please report security vulnerabilities by emailing our security team. We ask that you:

Email Us Directly

Send your report to security@hirance.com with a clear subject line and full details of the vulnerability.

Include Evidence

Provide steps to reproduce, screenshots, affected URLs, and your assessment of potential impact.

Encrypt Sensitive Data

If your report includes sensitive data, please encrypt your email using our PGP key (available on request).

Act in Good Faith

Do not access, modify, or delete user data beyond what is strictly necessary to demonstrate the vulnerability.

Safe Harbor

Hirance commits to the following protections for researchers who follow this policy in good faith:

  • We will not pursue civil or criminal action against you for good-faith security research conducted under this policy.
  • We will work with you to understand and resolve the issue promptly.
  • We will acknowledge your report within 3 business days.
  • We will keep your identity confidential if you request anonymity.
  • We may publicly thank researchers who report valid vulnerabilities (with your permission).
Important

Safe harbor applies only to research conducted within the scope of this policy and in accordance with applicable law. Activities that violate user privacy, disrupt services, or involve social engineering are not covered.

Response Timeline

Initial Acknowledgement

Within 3 business days

Triage & Severity Assessment

Within 7 business days

Status Update

Every 14 days until resolved

Fix Deployment

Depends on severity (critical: ≤7 days)

In-Scope Vulnerability Types

  • Remote code execution (RCE)
  • SQL injection and NoSQL injection
  • Cross-site scripting (XSS) — stored or reflected
  • Cross-site request forgery (CSRF) affecting sensitive actions
  • Authentication and session management flaws
  • Insecure direct object references (IDOR) exposing user data
  • Server-side request forgery (SSRF)
  • Privilege escalation vulnerabilities
  • Sensitive data exposure in APIs or client-side code

Out of Scope

The following are explicitly excluded from this policy:

  • Denial of service (DoS/DDoS) attacks
  • Spam or social engineering attacks against Hirance employees or users
  • Physical security vulnerabilities
  • Vulnerabilities in third-party services not under Hirance's control
  • Issues requiring unlikely or highly privileged user interaction
  • Self-XSS or attacks requiring the victim to install malware
  • Missing security headers without a demonstrated exploit path

Contact

Security Team — Hirance Private Limited

Email: security@hirance.com

General: hello@hirance.com

Phone: +91 7309510718, +91 9151410718

Address: 8/4, Sector-4, Jankipuram, Lucknow – 226021, Uttar Pradesh, India

We review all reports and aim to respond within 3 business days. Thank you for helping keep Hirance safe for millions of job seekers and employers.