hej.
Discover hej
This English text is a courtesy translation. Only the French version is legally binding.

Security policy

hej is a SaaS platform operated by SARL ACTION GIRATOIRE. This page covers our responsible disclosure policy and the technical controls we enforce to protect your data.

Report a vulnerability

Email security@hej.fr. PGP available on request. Initial response within 48 business hours.

Ground rules

  • Provide a reproducible report (steps, URL, payload, impact).
  • Do not access, modify or delete data belonging to other users.
  • No denial-of-service, brute-force, or spam attacks against our production systems.
  • Honour a reasonable disclosure window (90 days by default).

Safe harbor

Good-faith research that follows this policy will not be subject to civil or criminal action.

Controls

  • Transport: TLS 1.2+ mandatory, HSTS preloaded (2 years, includeSubDomains, preload).
  • Multi-tenant isolation: every query is scoped by organizationId. RBAC is enforced server-side (never UI-only).
  • Passwords: zxcvbn scoring, Have I Been Pwned lookup (k-anonymity SHA-1), bcrypt hashing, TOTP 2FA + WebAuthn passkeys.
  • Strict CSP: no unsafe-eval, frame-ancestors 'none', object-src 'none'.
  • Supply chain: CycloneDX SBOM on every release, daily SCA (OSV, npm audit, CodeQL, Semgrep), auto-merge for security patches, 24h SLA for HIGH/CRITICAL advisories.
  • Secrets: gitleaks + GitHub push protection. No secrets are ever stored in the repository.
  • Automated rollback: a post-deploy smoke test promotes the previous version when health probes fail.

Data

Hosted in the EU (Vercel + Neon). Encrypted backups, 30-day retention. Your data remains yours — see our privacy policy.

Last updated: 2026-04-20.