CorelyHR

Responsible disclosure

Report a security concern responsibly.

We welcome good-faith reports that help improve the security of CorelyHR and our customers’ data.

How to report

Use the contact page and select Security concern. Include reproducible steps, the affected URL or component, and impact. Do not include credentials, personal data, or public proof-of-concept material.

Safe handling

Do not access, alter, or retain customer data beyond what is necessary to demonstrate a report. Avoid disruption, social engineering, and denial-of-service testing.

What happens next

We will review a report, confirm receipt where safe to do so, and coordinate remediation. This process is not a public promise of a bounty or response time.