Responsible
Disclosure.
Found a vulnerability? We want to hear about it. Good-faith researchers are always protected.
Illustrative correspondence
A report becomes a conversation.
Scrub through a fictional disclosure exchange. Context stays attached as the discussion develops; these times are not response commitments.
Disclosure correspondence timeline
How to report
Three steps. 24-hour SLA.
01
Report
Email security@hives.com with a detailed description of the vulnerability, reproduction steps, and affected components.
02
Triage
Our security team acknowledges within 24 hours. We assess severity, assign a tracking ID, and begin remediation.
03
Resolution
We fix the issue, verify the patch, and notify you. Public disclosure after 90 days or upon fix, whichever comes first.
Program details
Scope and safe harbor.
In scopehives.com, api.hives.com, console.hives.com, all production endpoints
Out of scopeThird-party services, social engineering, denial of service attacks
Bounty range$500 - $25,000 based on severity and impact
Safe harborGood-faith security research is protected. We will not pursue legal action against researchers acting in good faith.