Skip to content

Security

Last updated: 9 October 2026

Hia holds information practitioners trust us with, so we want to hear about any weakness you find. This page says how to report one and describes the safeguards we can stand behind.

Report a vulnerability

Email hey@gethia.com with the subject “Security”. A machine-readable version of this policy is at /.well-known/security.txt.

Please include:

  • What you found and which page, endpoint or feature it affects.
  • Steps to reproduce it, and any proof of concept or screenshots.
  • What you think an attacker could do with it.
  • How to reach you, if you want a reply.

We aim to acknowledge reports within 3 working days and will tell you what we decide to do. Please give us a reasonable chance to fix an issue before you share it publicly.

Scope and good faith

In scope: the Hia web app and its API. Out of scope: other people's services we connect to (Meta, Google, payment providers), social engineering of our staff or users, physical attacks, and denial-of-service testing.

Please do not access, change or delete data that is not yours, and stop and tell us if you encounter personal data. If you act in good faith within this policy, we will not pursue action against you for your research. We do not run a bug bounty and cannot promise payment for reports.

Safeguards in place today

  • Access credentials for connected accounts (including Meta tokens) are encrypted at rest with AES-256-GCM, decrypted only at the moment a request to the provider is made, and never shown in the app.
  • Each practice's data is separated from every other practice's on every query.
  • Notifications from providers are verified by signature before they are acted on.
  • Connections use HTTPS, and passwords are stored only as one-way hashes.

Hia does not currently hold formal security certifications. No system is perfectly secure, and we would rather you told us about a problem than we found out later.