Vertices Security Disclosure

Vertices is committed to protecting the security and privacy of our users. We welcome responsible reports of security vulnerabilities to help us improve our services.

1. Scope

This disclosure applies to vulnerabilities in Vertices services that we directly control, including:

  • Website: www.verticeshq.com
  • Mobile apps
  • APIs and backend services
  • AI-powered features (such as resume analysis and job recommendations)

Not in scope:

  • Third-party services, platforms, or tools we integrate but do not control (e.g., Azure OpenAI infrastructure, email providers).
  • User accounts or data that is not your own.

2. How to Report

If you discover a security vulnerability:

  1. Please report it responsibly via our Report a Bug Form.
  2. Provide sufficient information for us to reproduce and understand the issue, including:

    • Steps to reproduce
    • Screenshots or videos (if relevant)
    • Any relevant system information (browser, OS, app version, etc.)

3. Safe Harbor

Researchers who act in good faith to report security vulnerabilities will not face legal action. Good faith means:

  • Testing only within the scope defined above
  • Avoiding exploitation of vulnerabilities
  • Not accessing data beyond what is necessary to demonstrate the issue

4. Response and Timeline

  • We will acknowledge receipt of your report within 3 business days.
  • We will work to resolve verified vulnerabilities as quickly as possible.
  • We may follow up with additional questions to clarify your report.

5. Rewards / Recognition

While Vertices currently does not have a formal bug bounty program, we may publicly acknowledge researchers who responsibly report vulnerabilities (with your consent).

6. Contact

For any questions about this Security Disclosure, contact us at:

 info@verticeshq.com