Hirance Private Limited ("Hirance") takes the security of its platform, mobile application, and user data extremely seriously. If you have discovered a security vulnerability in any of our systems, we encourage you to disclose it to us responsibly through this policy.
Scope
This policy applies to security vulnerabilities discovered in Hirance's digital assets including:
- hirance.com and all subdomains
- The Hirance mobile application (Android)
- Hirance backend APIs and infrastructure
- Employer and candidate portals
How to Report a Vulnerability
Please report security vulnerabilities by emailing our security team. We ask that you:
Send your report to security@hirance.com with a clear subject line and full details of the vulnerability.
Provide steps to reproduce, screenshots, affected URLs, and your assessment of potential impact.
If your report includes sensitive data, please encrypt your email using our PGP key (available on request).
Do not access, modify, or delete user data beyond what is strictly necessary to demonstrate the vulnerability.
Safe Harbor
Hirance commits to the following protections for researchers who follow this policy in good faith:
- We will not pursue civil or criminal action against you for good-faith security research conducted under this policy.
- We will work with you to understand and resolve the issue promptly.
- We will acknowledge your report within 3 business days.
- We will keep your identity confidential if you request anonymity.
- We may publicly thank researchers who report valid vulnerabilities (with your permission).
Safe harbor applies only to research conducted within the scope of this policy and in accordance with applicable law. Activities that violate user privacy, disrupt services, or involve social engineering are not covered.
Response Timeline
Initial Acknowledgement
Within 3 business days
Triage & Severity Assessment
Within 7 business days
Status Update
Every 14 days until resolved
Fix Deployment
Depends on severity (critical: ≤7 days)
In-Scope Vulnerability Types
- Remote code execution (RCE)
- SQL injection and NoSQL injection
- Cross-site scripting (XSS) — stored or reflected
- Cross-site request forgery (CSRF) affecting sensitive actions
- Authentication and session management flaws
- Insecure direct object references (IDOR) exposing user data
- Server-side request forgery (SSRF)
- Privilege escalation vulnerabilities
- Sensitive data exposure in APIs or client-side code
Out of Scope
The following are explicitly excluded from this policy:
- Denial of service (DoS/DDoS) attacks
- Spam or social engineering attacks against Hirance employees or users
- Physical security vulnerabilities
- Vulnerabilities in third-party services not under Hirance's control
- Issues requiring unlikely or highly privileged user interaction
- Self-XSS or attacks requiring the victim to install malware
- Missing security headers without a demonstrated exploit path
Contact
Security Team — Hirance Private Limited
Email: security@hirance.com
General: hello@hirance.com
Phone: +91 7309510718, +91 9151410718
Address: 8/4, Sector-4, Jankipuram, Lucknow – 226021, Uttar Pradesh, India
We review all reports and aim to respond within 3 business days. Thank you for helping keep Hirance safe for millions of job seekers and employers.