Responsible disclosure
Report a security concern responsibly.
We welcome good-faith reports that help improve the security of CorelyHR and our customers’ data.
How to report
Use the contact page and select Security concern. Include reproducible steps, the affected URL or component, and impact. Do not include credentials, personal data, or public proof-of-concept material.
Safe handling
Do not access, alter, or retain customer data beyond what is necessary to demonstrate a report. Avoid disruption, social engineering, and denial-of-service testing.
What happens next
We will review a report, confirm receipt where safe to do so, and coordinate remediation. This process is not a public promise of a bounty or response time.