Responsible Disclosure Policy
1. About this policy
We want Vpply Interview to be safe for the employers and candidates who use it. If you believe you have found a security vulnerability in our website or platform, we would like to hear from you. This policy explains how to report it, what we will do in return, and the rules we ask you to follow while you look.
2. How to report a vulnerability
Email our security team at security@vpply.com. Please send security reports there rather than to our sales or support contacts, social media or public forums.
To help us understand and fix the issue quickly, please include:
- a description of the vulnerability and the type of issue;
- the affected URL, page or API endpoint;
- step-by-step instructions to reproduce it, including any proof-of-concept code, requests or screenshots;
- the impact: what an attacker could do with it, and whose data or accounts would be at risk; and
- how we can contact you, and whether you would like to be credited.
We don't currently offer encrypted email. If your report would need to include sensitive details, such as someone else's personal information, send us a description without them first and we will agree a safer way to share the rest.
3. What we commit to
When you report a vulnerability in line with this policy, we will:
- acknowledge your report within 2 business days;
- confirm whether we can reproduce the issue, and triage it by severity;
- aim to fix confirmed critical issues within 7 days and high-severity issues within 30 days;
- keep you updated on our progress, and tell you when the issue is fixed; and
- credit you publicly for the discovery if you would like us to, once the issue is fixed.
We don't run a bug bounty programme and don't offer payment or rewards for reports.
4. Scope
In scope
- https://vpply.com (this website);
- https://interview.vpply.com (the employer dashboard);
- https://i.interview.vpply.com (the candidate interview app); and
- https://api.interview.vpply.com (the Vpply Interview API).
Out of scope
- denial of service attacks, or load or stress testing;
- social engineering or phishing of our staff, customers or candidates;
- physical attacks against our offices, staff or equipment;
- spam, or sending unsolicited messages through our forms or services;
- third-party services we use (for example, our hosting, email and payment providers). Report issues in those services to the provider under its own disclosure programme;
- output from automated scanners without a demonstrated impact; and
- accessing, modifying or keeping other people's data beyond the minimum needed to show the issue.
If you are unsure whether something is in scope, email us before you test it.
5. Rules for testing
While researching, please:
- only test against accounts you own or have the account holder's permission to use;
- stop as soon as you have shown the issue exists, and report it to us straight away;
- if you come across other people's personal information, stop, don't copy or keep it, and tell us in your report;
- don't degrade, disrupt or damage our services or anyone's data; and
- don't disclose the issue publicly or to anyone else until it has been fixed or 90 days have passed since your report, whichever comes first, unless we agree otherwise with you.
6. Safe harbour
If you make a good-faith effort to follow this policy, we will not take legal action against you in relation to your research.
This policy can only authorise testing of systems Vpply controls. It does not cover the third-party services listed as out of scope, and it does not cover research that breaks the rules above.
7. Changes to this policy
We may update this policy from time to time. The current version will always be available at this page, and the date at the top shows when it was last updated. A machine-readable pointer to it is published at vpply.com/.well-known/security.txt.