generated: '2026-09-13' method: searched source: https://legal.here.com/en-gb/security program: published: true type: coordinated-disclosure bug_bounty: false policy_url: https://legal.here.com/en-gb/security contact_email: security@here.com abuse_email: abuse@here.com authority_request_email: authority.request@here.com dns_iodef: mailto:security@here.com (CAA iodef record on here.com and hereapi.com) security_txt: false security_txt_note: No /.well-known/security.txt was served on any HERE host probed 2026-09-13; the policy is published as an HTML page instead. disclosure_terms: - rule: public_disclosure_window detail: Public disclosure is permitted 90 days after HERE acknowledges acceptance of the report, or after the bug is fixed and verified by the reporter. - rule: scope_limits detail: Denial-of-service testing and data extraction beyond the minimum needed to demonstrate the issue are prohibited; automated scanning tools are not permitted. - rule: report_format detail: Plain-text technical description plus reproduction steps; screenshots (jpeg/png) and pcap traffic dumps accepted as supporting evidence. - rule: test_accounts detail: Researchers must test with their own accounts and must not impact other service users. evidence: - url: https://legal.here.com/en-gb/security status: 200 - url: https://legal.here.com/security status: 200