Vulnerability Disclosure Policy
Last updated: January 5, 2026
Report a Vulnerability
Found a security issue? We appreciate your help in keeping RECRUITED secure.
security@recruitedcrm.com1. Introduction
RECRUITED values the security community and believes that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our users. We are committed to working with security researchers who help us improve our security.
This policy describes how to report vulnerabilities to us, what we expect from you, and what you can expect from us.
2. Scope
2.1 In Scope
- recruitedcrm.com and all subdomains
- RECRUITED web application
- RECRUITED API endpoints
- Authentication and authorization systems
- Gmail OAuth integration security
2.2 Out of Scope
- Third-party services and applications (Google, Stripe, etc.)
- Physical security testing
- Social engineering attacks against employees or users
- Denial of service (DoS/DDoS) attacks
- Spam or phishing attacks
- Issues in third-party libraries without demonstrable impact
3. How to Report
Please submit vulnerability reports to security@recruitedcrm.com
3.1 What to Include
- Description: Clear explanation of the vulnerability
- Steps to Reproduce: Detailed steps to replicate the issue
- Impact: Potential security impact if exploited
- Proof of Concept: Working PoC code, screenshots, or video (if applicable)
- Affected Components: URLs, parameters, or features involved
- Your Contact: Email for follow-up communication
Encryption: If you need to send sensitive information, please request our PGP key.
4. Safe Harbor
We consider security research conducted consistent with this policy to be:
- Authorized: We will not pursue legal action against you
- Helpful: We appreciate your effort to improve our security
- Protected: We will not take adverse action based on your report
This safe harbor applies as long as you:
- Act in good faith
- Do not access, modify, or delete user data beyond what is necessary to demonstrate the vulnerability
- Follow the guidelines in this policy
- Report vulnerabilities promptly
5. Response Timeline
- Within 48 hours:Initial acknowledgment of your report
- Within 5 business days:Initial triage and severity assessment
- Within 30 days:Status update on remediation progress
- Within 90 days:Target resolution for most vulnerabilities
6. Coordinated Disclosure
We request that you:
- Give us reasonable time to investigate and remediate before public disclosure
- Coordinate disclosure timing with us
- Do not disclose vulnerability details to third parties without our consent
We typically request a 90-day disclosure window, but we're flexible based on the complexity of the fix. We will work with you to find a mutually agreeable disclosure timeline.
7. Recognition
We appreciate security researchers who help us improve our security. With your permission, we may:
- Acknowledge your contribution (if you consent)
- Provide a letter of recognition upon request
Note: We do not currently offer monetary rewards, but we may consider this in the future.
8. Prohibited Activities
When testing, please do NOT:
- Access, download, or modify data belonging to other users
- Execute denial of service attacks
- Send unsolicited messages to users
- Perform physical security testing
- Use social engineering against employees or users
- Test vulnerabilities on production systems in a destructive manner
- Publicly disclose vulnerabilities before they are resolved
- Violate any applicable laws
9. Questions
If you have questions about this policy or need clarification before testing, please contact us at security@recruitedcrm.com.
10. Contact Information
Security Team
Email: security@recruitedcrm.com
For general inquiries, please use contact@recruitedcrm.com