Security policy
hej is a SaaS platform operated by SARL ACTION GIRATOIRE. This page covers our responsible disclosure policy and the technical controls we enforce to protect your data.
Report a vulnerability
Email security@hej.fr. PGP available on request. Initial response within 48 business hours.
Ground rules
- Provide a reproducible report (steps, URL, payload, impact).
- Do not access, modify or delete data belonging to other users.
- No denial-of-service, brute-force, or spam attacks against our production systems.
- Honour a reasonable disclosure window (90 days by default).
Safe harbor
Good-faith research that follows this policy will not be subject to civil or criminal action.
Controls
- Transport: TLS 1.2+ mandatory, HSTS preloaded (2 years,
includeSubDomains,preload). - Multi-tenant isolation: every query is scoped by
organizationId. RBAC is enforced server-side (never UI-only). - Passwords: zxcvbn scoring, Have I Been Pwned lookup (k-anonymity SHA-1), bcrypt hashing, TOTP 2FA + WebAuthn passkeys.
- Strict CSP: no
unsafe-eval,frame-ancestors 'none',object-src 'none'. - Supply chain: CycloneDX SBOM on every release, daily SCA (OSV, npm audit, CodeQL, Semgrep), auto-merge for security patches, 24h SLA for HIGH/CRITICAL advisories.
- Secrets: gitleaks + GitHub push protection. No secrets are ever stored in the repository.
- Automated rollback: a post-deploy smoke test promotes the previous version when health probes fail.
Data
Hosted in the EU (Vercel + Neon). Encrypted backups, 30-day retention. Your data remains yours — see our privacy policy.
Last updated: 2026-04-20.