Skip to content

Security

Report a security issue

If you have found a weakness in Hoihoi, please tell us.

This page says where to send it, what you can expect back from us, and what we promise in return. It is the policy referenced by our security.txt.

How to report

Email security@hoihoi.app. Include enough for us to reproduce the problem: the URL or endpoint, the steps you took, and what you saw. If you need to send something sensitive, say so in your first message and we will arrange a channel for it.

You do not need a working exploit. A clear description of the weakness is enough.

What we commit to

  • We acknowledge your report within 2 working days.
  • We tell you within 5 working days whether we think it is valid, and what we need from you if we are not sure.
  • We update you at least every 10 working days while the issue is open.
  • We fix a critical issue within 30 days, or explain to you why it is taking longer.
  • We tell you when it is fixed, and we credit you by name if you would like that.

What is in scope

  • hoihoi.app and its subdomains, including the app at /app and the client portal at /portal.
  • The three pages addressed by a link rather than a login: pay an invoice, sign a document, and book a slot.
  • The callback used when you connect a calendar or Drive integration.
  • Our database API, and in particular anything that lets one workspace reach another workspace's data.

What is out of scope

  • Anything running on a third party's infrastructure. Report those to the third party, and tell us as well if it affects your Hoihoi account.
  • Findings that need a compromised device, a modified browser, or physical access to someone's machine.
  • Missing headers or TLS settings with no demonstrated impact, and scanner output nobody has verified by hand.
  • Social engineering of our people or our customers, spam, and denial of service.

Safe harbour

If you follow this policy, we will treat your research as authorised. We will not pursue legal action against you and we will not report you to law enforcement. In return, please:

  • Use only test accounts you control, and stop as soon as you have confirmed the problem.
  • Never access, change, download, or keep another customer's data. If you reach personal data by accident, stop, tell us straight away, and delete it.
  • Never degrade the service for other people: no high-volume automated scanning, no denial of service, no spam.
  • Give us a reasonable chance to fix the issue before you write about it publicly. We will agree a date with you.

What we do not offer

We do not run a paid bug-bounty programme, and there is no monetary reward. We would rather say that here than have you find out after you have spent your evening on it.