Our commitment
We take the security of AIHR BD and the data our customers entrust to us very seriously. We welcome reports from security researchers, customers and the wider community, and we are committed to working with you to triage, validate and remediate vulnerabilities quickly.
Scope
The following assets are in scope for responsible disclosure:
aihrbd.comand all subdomains- The AIHR BD web application and its API endpoints
- Server functions and APIs operated by AIHR BD
- Authentication, billing and email flows operated by AIHR BD
Out of scope: third-party infrastructure providers we depend on, customer-tenant content, and denial-of-service or volumetric attacks.
Rules of engagement
- Only test against accounts you own or have explicit permission to test.
- Do not access, modify, or delete data belonging to other tenants or users.
- Do not run automated scanners that generate significant traffic without prior approval.
- Do not perform social engineering, phishing or physical attacks against staff, customers or vendors.
- Stop testing and report immediately if you encounter personal data or production secrets.
How to report
Send your report to . Please include:
- A clear description of the issue and the impact.
- Steps to reproduce, including any proof-of-concept payloads.
- The affected URL, endpoint or screen.
- Your name or handle if you would like to be credited.
For sensitive reports you can request our PGP key in your initial email and we will respond with it before you send any further details.
What to expect from us
- Acknowledgement of your report within 24 hours.
- Triage and initial assessment within 3 working days.
- Regular status updates while we work on a fix.
- Public credit (with your permission) once the issue is resolved.
- No legal action against researchers who follow this policy in good faith.
Safe harbour
Research conducted in accordance with this policy is considered authorised. We will not pursue or support any legal action related to good-faith research, and we will work to make sure you are not penalised by anti-hacking laws or our Terms of Service for activity that complies with these rules.
Rewards & acknowledgements
AIHR BD does not currently run a paid bug-bounty programme. We do offer public acknowledgement in our security advisories and, at our discretion, swag or service credits for high-impact reports.
Researchers who report valid issues are credited on our Security Hall of Fame, and you can read more about our controls on the security overview page.