HexaPrime hexagon brand mark
Security

Responsible Disclosure

Found a vulnerability in a HexaPrime system? Here is how to report it, and what happens next.

Disclosure

Reporting a vulnerability

Report in good faith and we will not pursue legal action against you.

Last updated 9 September 2026

Security is what we do for a living, so we take reports about our own systems seriously. If you believe you have found a vulnerability in a HexaPrime system, we want to hear from you, and we will not pursue legal action against anyone who follows this policy in good faith.

1. Scope

This policy covers systems that HexaPrime owns and operates, including hexaprime.me and its subdomains, and the public facing services we run under the hexaprime.me domain.

It does not cover client systems. If you have found an issue in a system belonging to one of our clients, report it to that organisation directly. Where you cannot identify a contact, write to us and we will pass the report on, but we cannot authorise testing against a system we do not own.

2. How to report

Email info@hexaprime.me with "Security report" in the subject line. Please include:

  • The affected system, URL or endpoint.
  • The vulnerability type and its likely impact.
  • Clear steps to reproduce, including any payload, request or proof of concept.
  • Any screenshots or logs that help, and how you would like to be credited.

Write in English or Arabic. We will acknowledge your report within two business days.

3. What we ask of you

  • Give us a reasonable opportunity to fix the issue before disclosing it to anyone else. We aim to remediate within 90 days and will keep you informed.
  • Make a good faith effort to avoid privacy violations, data destruction and interruption of service.
  • Access only the minimum data needed to demonstrate the issue, and stop as soon as you have. Do not download, retain, copy or share data belonging to us or to our clients.
  • Delete any data you obtained as soon as the report is closed, and tell us you have done so.
  • Do not use social engineering, phishing or physical intrusion against our staff, our offices or our suppliers.
  • Do not run denial of service, volumetric, brute force or automated scanning that degrades a service for anyone else.
  • Do not plant a backdoor, escalate beyond proof, or take any action that would be destructive or persistent.

4. Out of scope

The following are generally not accepted unless you can show a realistic, demonstrable impact:

  • Findings from automated scanners without a working proof of concept.
  • Missing security headers, cookie flags or TLS configuration preferences with no exploitable consequence.
  • Clickjacking or self cross site scripting on pages with no sensitive action.
  • Rate limiting or brute force on non authentication endpoints.
  • Email configuration findings such as SPF, DKIM or DMARC without an accompanying spoofing proof.
  • Software version disclosure, and vulnerabilities affecting only unsupported or end of life browsers.
  • Reports about third party services we do not control, including our hosting platform. Those go to the provider.

5. What you can expect from us

  • Acknowledgement within two business days.
  • A triage decision and severity assessment within ten business days.
  • Regular updates until the issue is closed.
  • Public credit for the reporter, where you want it and once the fix is live.

We do not currently operate a paid bug bounty. Nothing in this policy creates an obligation to pay a reward.

6. Safe harbour

If you make a good faith effort to comply with this policy during your research, we will consider your activity authorised, we will not initiate or support legal action against you in relation to it, and we will make it known that you acted in accordance with this policy if a third party raises a concern. This does not waive the rights of any third party, and it does not authorise activity that breaks UAE law.

7. Contact

info@hexaprime.me, +971 4 203 6500, or HexaPrime Technology, Office 207, Lootah Group HQ, Umm Ramool, Dubai, United Arab Emirates, PO Box 19561.

Ready to Secure Your Business?

Protect your organization with enterprise-grade cybersecurity, cloud, and managed IT solutions tailored to your business needs.