Legal

Vulnerability Disclosure Policy

A safe reporting path for good-faith security research affecting PulseHireX.

Effective September 13, 2026

1. How to report

Send reports privately to info@pulsehirex.com with the affected URL or feature, reproduction steps, impact and a safe contact method. Do not include customer passwords, recovery codes, authenticator secrets, private keys or unnecessary personal data.

2. Safe harbor conditions

Act in good faith, minimize access, stop after demonstrating impact, avoid persistence and data changes, and give us reasonable time to investigate before public disclosure. Do not use denial of service, social engineering, physical attacks, automated volume testing, extortion or access to data beyond what is needed.

3. Our response

We aim to acknowledge valid reports, investigate, communicate material progress and remediate based on severity. This policy does not promise a bounty and does not authorize testing of third-party client systems.