generated: '2026-08-22' method: searched source: https://hiverhq.com/disclosure name: Hiver Vulnerability Disclosure Policy published: true policy_url: https://hiverhq.com/disclosure policy_http_status: 200 contact: email: security@hiverhq.com form: false security_txt: served: false note: >- No /.well-known/security.txt on any Hiver host, so the disclosure address is only discoverable by reading the marketing-site footer. See well-known/hiver-well-known.yml. bug_bounty: program: false platform: none rewards: false stated_intent: >- 'we will come up with a rewards program for community engagement in the future' safe_harbor: not stated response_commitment: level: acknowledge-only quote: >- 'Until then, we will continue to "Only Acknowledge" security research reported at security@hiverhq.com' sla: none stated scope: not published linked_from: - https://hiverhq.com/security-center - https://hiverhq.com/ (footer, 'Vulnerability Disclosure') assessment: >- A real, first-party, publicly reachable disclosure policy with a working reporting address - but explicitly acknowledge-only, with no bounty, no safe-harbour language, no scope statement and no response SLA. Adding a security.txt and a safe-harbour clause would be the two cheapest improvements.