Responsible Disclosure.
Hael takes the security of its platform and the data it processes seriously. We welcome security researchers and customers reporting vulnerabilities to us privately, so we can fix them before they cause harm. This policy sets out how to report, what is in scope, and the safe-harbour commitment we offer to good-faith researchers.
How to report
Report vulnerabilities to security@hael.ai. Please include a clear description of the issue, steps to reproduce, the affected URL or component, the impact you have observed, and any proof-of-concept material.
We acknowledge reports within 2 business days, provide a triage assessment within 5 business days, and aim to remediate critical issues within 14 days. Timelines for lower-severity issues are agreed with the reporter case by case.
Scope
The following are in scope:
- The Hael web application and marketing site.
- Hael's public API endpoints under
/api/public/*.
Out of scope:
- Findings from automated scanners without a clear, reproducible impact.
- Missing security headers on non-sensitive pages, unless exploitable.
- Social engineering of Hael employees, contractors, or customers.
- Physical attacks against Hael facilities.
- Denial-of-service attacks or testing that degrades service for other users.
- Findings against third-party sub-processors — please report those directly to the vendor and, if relevant, notify us.
- Reports based solely on software versions without a demonstrated vulnerability.
Safe harbour
We will not pursue legal action against researchers who, in good faith, comply with this policy: report privately to security@hael.ai, avoid privacy violations and destruction of data, do not degrade our service, use only test accounts you control, and give us a reasonable window to remediate before any public disclosure (typically 90 days, by mutual agreement). If you are uncertain whether testing is permitted, contact us first.
Coordinated disclosure
We work with reporters to coordinate disclosure timelines and credit researchers in our security advisories where they wish to be credited. We ask that reporters do not publish details before a fix has been deployed.
What we don't offer
Hael does not currently operate a paid bug-bounty programme. Recognition and coordinated disclosure are how we acknowledge reports today.
Contact
Security reports: security@hael.ai. General security questions: see the Trust Center or the Security page.