
Found a vulnerability in a HexaPrime system? Here is how to report it, and what happens next.
Report in good faith and we will not pursue legal action against you.
Security is what we do for a living, so we take reports about our own systems seriously. If you believe you have found a vulnerability in a HexaPrime system, we want to hear from you, and we will not pursue legal action against anyone who follows this policy in good faith.
This policy covers systems that HexaPrime owns and operates, including hexaprime.me and its subdomains, and the public facing services we run under the hexaprime.me domain.
It does not cover client systems. If you have found an issue in a system belonging to one of our clients, report it to that organisation directly. Where you cannot identify a contact, write to us and we will pass the report on, but we cannot authorise testing against a system we do not own.
Email info@hexaprime.me with "Security report" in the subject line. Please include:
Write in English or Arabic. We will acknowledge your report within two business days.
The following are generally not accepted unless you can show a realistic, demonstrable impact:
We do not currently operate a paid bug bounty. Nothing in this policy creates an obligation to pay a reward.
If you make a good faith effort to comply with this policy during your research, we will consider your activity authorised, we will not initiate or support legal action against you in relation to it, and we will make it known that you acted in accordance with this policy if a third party raises a concern. This does not waive the rights of any third party, and it does not authorise activity that breaks UAE law.
info@hexaprime.me, +971 4 203 6500, or HexaPrime Technology, Office 207, Lootah Group HQ, Umm Ramool, Dubai, United Arab Emirates, PO Box 19561.
Protect your organization with enterprise-grade cybersecurity, cloud, and managed IT solutions tailored to your business needs.