How to report
Email security@itya.ai. One report per issue. A useful report contains:
- the affected host, endpoint or page, and the date and time you tested;
- the steps to reproduce, in enough detail that we can follow them exactly;
- what an attacker gains — the impact, not just the class of bug;
- any proof-of-concept payload, request or screenshot; and
- how you would like to be credited, or that you would prefer not to be.
Please do not open a public issue, post the details publicly, or file it through the support form. If you need to send something sensitive and want it encrypted, say so in your first email and we will arrange a key exchange before you send it.
What we commit to
- Acknowledgement within 3 business days, from a person, not an autoresponder.
- Triage decision within 10 business days: whether we accept it, our severity assessment, and the reasoning if we disagree with yours.
- Progress updates at least every 14 days until the issue is closed.
- Fix targets of 7 days for critical, 30 days for high, and 90 days for medium and low severity, measured from triage. If we are going to miss one, we will tell you before the deadline rather than after it.
- Coordinated disclosure. We will agree a publication date with you. We will not ask you to stay quiet indefinitely.
Scope
In scope:
- The Itya web application and its public marketing, legal and status pages.
- The Itya API, including the public booking, consent, data-request and support endpoints.
- The embedded interview room and its media and consent handling.
- Authentication, session handling, workspace isolation, permission enforcement, and any path that lets one workspace reach another's data.
- Anything that exposes candidate personal data, recordings or transcripts.
Out of scope:
- Denial of service, volumetric or stress testing, and anything that degrades the service for real users.
- Social engineering, phishing, or physical attacks against Itya staff or offices.
- Findings from an automated scanner with no demonstrated impact, and best-practice observations such as a missing header where you cannot show it is exploitable.
- Reports about our third-party providers' own infrastructure — report those to the provider. Tell us if the issue is in how Itya uses them.
- Vulnerabilities requiring a rooted device, a physically compromised browser, or a stolen unlocked session.
- Self-XSS, missing rate limits with no demonstrated impact, and email spoofing of domains we do not send from.
Safe harbour
If you make a good-faith effort to follow this policy, Itya will treat your research as authorised conduct. We will not bring a civil claim or refer you for prosecution under computer-misuse or anti-circumvention law, and we will not take action for a breach of our terms of service arising from your research. If a third party brings an action against you for research that followed this policy, we will make it known that your activity was authorised.
Good faith means, at a minimum:
- Test only against accounts and workspaces you own or have explicit written permission to test.
- Stop as soon as you have confirmed a vulnerability. Do not pivot, do not escalate further than you need to prove impact, and do not read, copy, modify or delete data that is not yours.
- If you access personal data by accident, stop, do not save it, tell us immediately, and delete any copy once we confirm.
- Do not degrade the service, and do not test in a way that reaches real candidates.
- Give us reasonable time to fix the issue before you disclose it.
This safe harbour cannot bind third parties. If your testing would touch a provider on our subprocessor list, their policy applies to that part, not ours.
Recognition, not a bounty
Itya does not run a paid bug bounty and does not promise a reward. We would rather be honest about that up front than imply a payment that never comes.
What we do offer, for a valid report you are the first to send: public credit under the name or handle you choose, a written confirmation of the finding and its resolution that you can use professionally, and a direct line to the engineer who fixed it. Ask to stay anonymous and we will keep you out of the record entirely.
Security questionnaires and evaluations
For an evaluation rather than a vulnerability report, the same address works. Send your questionnaire, your transfer-impact-assessment request or your vendor-risk template to security@itya.ai.
Before you send one, the security page, the data processing addendum and the subprocessor list answer most of what a standard template asks. Itya does not hold a SOC 2 or ISO 27001 certification and has not commissioned a third-party penetration test, so there is no report to request — we would rather say that than leave you waiting for one.