HULO Global Limited takes the security of our websites, hosted services, software and customers’ data seriously. If you believe you have found a security vulnerability, we want to hear from you. This policy tells you how to report it and what we ask in return. It is also published in machine-readable form at /.well-known/security.txt.
1. Scope
This policy covers:
- huloglobal.com and its subdomains;
- the hosted PayrollOS service;
- our Vendure plugins, their licence portal and licence server, and their documentation;
- software we publish on npm and GitHub under the HULO Global name.
It does not cover: third-party services we use (report to them directly); customers’ own stores and deployments of our plugins (report to the store owner); social-engineering, phishing or physical attacks against our staff or premises; denial-of-service testing; or findings that only affect users with outdated browsers or that require an already-compromised device.
2. How to report
Email [email protected] with the subject “Security vulnerability”. Include:
- the product, URL or component affected and the version if known;
- a description of the issue and its potential impact;
- step-by-step instructions or a proof of concept sufficient for us to reproduce it;
- any screenshots or logs, with personal data removed;
- how you would like to be credited, if at all.
If your report contains sensitive material, tell us and we will provide a secure channel before you send it. Please do not put exploit details in a public issue tracker, forum or social-media post.
3. What we ask of you
- Act in good faith and avoid privacy violations, destruction of data, and degradation of our services.
- Only access, use or exfiltrate the minimum data necessary to demonstrate the issue. If you encounter personal data, licence keys, payroll data or credentials, stop, do not copy them, and tell us.
- Do not test using accounts, licences or stores that are not yours, and do not attempt to move laterally into other customers’ data.
- Do not perform denial-of-service, brute-force, spam, or physical or social-engineering attacks.
- Give us a reasonable time to fix the issue before disclosing it publicly. We ask for 90 days from our acknowledgement, or longer by agreement for complex issues.
- Comply with the law. This policy does not authorise activity that is unlawful in your jurisdiction.
4. What you can expect from us
- Acknowledgement of your report within two working days.
- An initial assessment and expected timeline within ten working days.
- Updates as we investigate and fix the issue, and confirmation when it is resolved.
- Credit on request in the relevant release notes once the fix is released, unless you prefer to remain anonymous.
- We will not pursue or support legal action against researchers who act in good faith and in accordance with this policy, and we consider such research authorised for the purposes of the Computer Misuse Act 1990 and our own terms.
We do not currently run a paid bug bounty. We may offer a token of thanks for reports of significant issues at our discretion.
5. Our security practices
We keep this short and factual. Public services sit behind a content-delivery network and web application firewall. Administrative access uses key-based authentication and is limited to named individuals. Data in transit is encrypted with TLS. Backups are encrypted and stored in two locations, one of them off-site, and restores are tested regularly. Dependencies are monitored for published vulnerabilities and updated on a fixed cadence, faster for critical issues. Payment card data is handled by our payment provider and never touches our servers. Customers of the hosted PayrollOS service can read more in the Support and security page.
6. Changes
We may update this policy at any time. The version date is at the top of the page and the Expires field in security.txt is refreshed annually.