Security Vulnerability Disclosure Policy

Last Updated: 01 May, 2026

Purpose

Hey Seva (SEVA) is committed to the security of our platform and the protection of our customers' and creators' data. We value the work of the security research community and welcome reports of vulnerabilities in our systems. If you believe you have found a security issue, we want to hear from you — and we will work with you in good faith to understand, validate, and fix it.

Scope

The following properties are in scope for security research under this policy:

- https://heyseva.com
- https://app.heyseva.com
-
APIs served under api.heyseva.com

Anything not listed above — including third-party services we integrate with (e.g., Shopify, TikTok, Meta, email providers, payment processors) — is out of scope under this policy. Please report issues with those services directly to the respective vendor.

Rules of Engagement (Prohibited Conduct)

While researching, you must not:
- Perform actions that could degrade, disrupt, or damage our Services or affect our users (e.g., spam, brute force, denial-of-service attacks, resource exhaustion).
- Access, modify, delete, or exfiltrate data that does not belong to you. If you encounter another user's or organization's data, stop immediately, do not save or share it, and include only the minimum detail necessary to describe the issue in your report.
- Use social engineering, phishing, or physical attacks against Hey Seva employees, contractors, offices, or infrastructure.
Test using accounts or organizations that do not belong to you. Use your own test account(s) only.
- Violate any applicable law or breach any agreement in the course of your research.
- Publicly disclose a vulnerability before we have confirmed a fix and agreed on disclosure (see "Coordinated Disclosure" below).

Safe Harbor

SEVA is committed to the security of our platform and the protection of our customers' and creators' data. We value the work of the security research community and welcome reports of vulnerabilities in our systems. If you believe you have found a security issue, we want to hear from you — and we will work with you in good faith to understand, validate, and fix it.

How to Report

Email security@heyseva.com with:
1. A description of the vulnerability and its potential impact.
2. Steps to reproduce (proof-of-concept code, screenshots, or video welcome).
3. The URL/endpoint and any relevant account identifiers (test accounts only)
4. Your disclosure intentions, if any.
Well-written reports with reproduction steps are triaged fastest. Reports consisting solely of automated scanner output without demonstrated impact will generally not be actionable.

What You Can Expect From Us

– Acknowledgment of your report within 2 business days.
– An open dialog and status updates as we validate and remediate.
– A remediation timeline for confirmed issues (typically within 90 days, faster for critical issues).
– Credit for the discovery, if you would like it, once the issue is resolved.

We do not currently operate a paid bug bounty program. We may, at our discretion, offer thanks, swag, or rewards for high-impact reports.

Coordinated Disclosure

We ask that you keep vulnerability details confidential until we have remediated the issue and notified affected customers if necessary. Where public disclosure is appropriate, we prefer to coordinate timing and content with you, and where possible publish simultaneously. We do not authorize public disclosure of security reports or details of our systems without our explicit written permission.

This policy does not grant permission to test systems or services owned by third parties, and does not waive any rights SEVA may have with respect to conduct outside the scope of this policy.


Image Gradient