Vulnerability Disclosure
Program
At HADESS, security is in our DNA. We partner with the security research community to identify and fix vulnerabilities. Valid reports are recognized in our Hall of Fame.
Vulnerability Disclosure Policy
HADESS is committed to the security of our platform and the data of our users. We welcome contributions from the security research community to help us identify potential vulnerabilities. This Vulnerability Disclosure Policy (VDP) outlines the rules of engagement and our commitment to working with researchers in good faith.
Scope
In Scope
career.hadess.io
Main platform (web application)
career.hadess.io/api/*
All REST API endpoints
Authentication flows
OAuth, session management, login/logout
Payment processing
Stripe and crypto payment integrations
User data handling
Profile, resume, and career data processing
Out of Scope
Severity Levels & Recognition
Rules of Engagement
Do Not Access User Data
Do not access, modify, or delete data belonging to other users. Create test accounts for testing.
Minimize Impact
Avoid actions that could degrade service availability. Stop testing if you discover credentials or sensitive data.
Responsible Disclosure
Give us 90 days to address the vulnerability before public disclosure. We may request extensions for complex issues.
Legal Safe Harbor
We will not pursue legal action against researchers who comply with this policy and act in good faith.
How to Report
Send your vulnerability report to [email protected] with the following information:
Vulnerability Type
Classify the vulnerability (XSS, SQLi, IDOR, RCE, etc.)
Affected Component
URL, API endpoint, or feature where the vulnerability exists
Steps to Reproduce
Clear, step-by-step instructions to reproduce the issue
Proof of Concept
Screenshots, HTTP requests/responses, or video demonstration
Impact Assessment
Describe the potential impact and affected users/data
Suggested Fix
Optional but appreciated: your recommendation for remediation
Hall of Fame
View our security researchers who have helped make HADESS safer