Responsible disclosure

If you find a security problem in InterviewStack for Recruiters, we want to hear about it, and we will deal with you fairly for telling us.

Last updated 9 September 2026.

Scope

hire.interviewstack.io and the recruiter product where it is served on app.interviewstack.io: the recruiter workspace, the candidate interview pages, the review links, the webhook deliveries and the API. Out of scope: our marketing site's content, third-party services we use (report those to the provider), and findings that need physical access or social engineering of our staff or customers.

Rules

  • Do not access, alter or download data that is not yours. If a candidate's or employer's data is exposed, stop, note what you saw, and report it; do not keep it.
  • Test against a workspace you created; email us and we will provide a test workspace with interview credits for good-faith research. Do not run denial-of-service or volume tests.
  • Give us a reasonable time to fix before any public disclosure; we will agree a date with you.

How to report

Email support@interviewstack.io with the subject "Security": what you found, where, how to reproduce it, and its impact. You will get an acknowledgement within two business days and a triage result within five business days.

What you can expect

  • We do not pursue researchers acting in good faith within these rules.
  • Target fix times: critical (data exposure, authentication bypass) within 7 days; high within 30 days; others in the normal release cycle. We tell you when the fix ships.
  • No paid bounty program today. Credit on this page on request once the fix is out.
Responsible disclosure | InterviewStack for Recruiters