5.1 Purpose
Hirfa welcomes the contribution of independent security researchers who responsibly identify and report vulnerabilities. This policy describes what is authorized, how to report, and what researchers can expect from us in return.
5.2 Scope
In scope:
- The Hirfa mobile application (iOS/Android)
- The Hirfa web application at gethirfa.com
- Hirfa's public API endpoints
Out of scope:
- Third-party services integrated with Hirfa (e.g., the payment gateway provider's own infrastructure) — please report those directly to the respective vendor.
- Social engineering attacks against Hirfa employees, contractors, or Users.
- Physical security attacks against Hirfa offices or personnel.
- Denial-of-Service (DoS/DDoS) attacks of any kind.
- Automated vulnerability scanning that generates high-volume traffic without prior coordination with
security@gethirfa.com.
5.3 Safe Harbor and Rules of Engagement
Research conducted in good faith and in compliance with this policy is considered authorized under Egyptian law, and Hirfa will not pursue legal action against researchers who:
- Do not access, modify, or delete data belonging to real Users beyond the minimum necessary to demonstrate the vulnerability.
- Immediately stop testing and report the issue upon discovering access to sensitive data, rather than continuing to explore further.
- Do not publicly disclose a vulnerability before Hirfa has had a reasonable opportunity to remediate it (a minimum of 90 days, or as mutually agreed).
- Do not perform any action that could degrade the availability or integrity of the Platform for other Users.
5.4 How to Report
Send a detailed report to security@gethirfa.com or submit through our Reporting System (Section 13), including:
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions.
- Screenshots, video, or proof-of-concept code where applicable (without exploiting further than necessary).
- Your preferred contact method and, optionally, a PGP key for encrypted correspondence.
For RFC 9116 security contact standards and PGP key verification, see our security.txt Declaration (Section 11) and raw /.well-known/security.txt file.
5.5 Our Commitment to Researchers
- Acknowledgment: within 72 hours of report receipt.
- Status updates: at least every 7 days until resolution.
- Resolution: critical vulnerabilities are prioritized for remediation on an expedited timeline.
- Recognition: researchers who agree to public acknowledgment will be listed in Hirfa's Security Hall of Fame. A formal bug-bounty rewards program may be introduced as the platform matures.