Security

How to report a vulnerability, what is in scope, and what we do with your data.

Effective date: August 25, 2026

If you have found a security problem in Hive Intelligence, tell us. This page is the policy referenced by our security.txt, and it is the fastest route to someone who can fix the issue.

Reporting a vulnerability

Report through our Telegram: send a direct message to a group admin rather than posting in the public channel, so the issue stays private until it is fixed. Include enough detail for us to reproduce it: the affected endpoint or surface, the steps, and what you were able to access or change. Include a proof of concept if you have one. Reports in English are handled fastest.

Please report privately and give us a chance to fix the issue before you publish. We do not run a paid bug bounty, and we do not offer monetary rewards. We do credit reporters who ask to be credited once a fix has shipped.

Response targets

  • Acknowledgement: within 3 business days of your report.
  • Triage and initial assessment: within 7 business days.
  • Status update: at least every 14 days while the issue is open.
  • Fix or documented mitigation: we target 90 days from triage, and sooner for anything that exposes customer data or allows unauthorized access.

We will tell you when the fix ships and agree a disclosure timeline with you.

Scope

In scope:

  • mcp.hiveintelligence.xyz: the hosted MCP server and its HTTP surface.
  • hiveintelligence.xyz and www.hiveintelligence.xyz: the marketing site, the dashboard, and the authentication flow.
  • The hive-intelligence CLI package published on npm.
  • The published agent skills and the SDK mirror.

Out of scope:

  • Third-party data providers and their APIs. Report those to the provider; tell us too if the issue is reachable through Hive.
  • Vendor-operated infrastructure that we do not control. Report those to the vendor named on our subprocessor list.
  • Findings from automated scanners with no demonstrated impact, missing best-practice headers with no exploit path, rate-limit tuning, and reports about email configuration that do not lead to spoofed mail actually being accepted.
  • Social engineering of our staff or users, physical attacks, and denial-of-service testing.
  • Data accuracy complaints. Those are a support matter, not a security one.

Safe harbour

If you make a good-faith effort to follow this policy while researching a vulnerability, Hive Intelligence will not bring or support a legal claim against you in connection with that research, and will treat your activity as authorized under the computer-misuse and anti-circumvention laws that apply to us. Good faith means you:

  • only test against accounts and data that belong to you;
  • stop as soon as you have confirmed a vulnerability, and do not pivot further into our systems;
  • do not access, modify, delete, or retain anyone else's data, and delete any that you encounter incidentally;
  • do not degrade the service with denial-of-service testing or bulk automated scanning that pushes real load;
  • give us a reasonable opportunity to fix the issue before disclosing it publicly.

This safe harbour is what we control. It cannot bind a third party, so it does not cover testing against our providers or our vendors. If a law enforcement or third party action is brought against you for activity we consider to have been in good faith under this policy, we will say so.

How we handle your credentials

  • API keys are issued and verified through a key-management provider. We store a key identifier and metadata, never a recoverable copy of the key, and a key is shown to you in full exactly once, at creation.
  • Sign-in is by a link emailed to your account address. There is no password to steal, and no password is stored.
  • You can revoke any key at any time from the dashboard. Revocation is immediate.
  • Upstream data providers are reached with Hive-managed keys, so using the hosted service does not require you to hand us a third-party credential.

Logging and retention

We log requests and telemetry to operate and secure the service. Tool arguments, response payloads, wallet addresses, and API key values are not written to telemetry. Retention periods are listed in section 6 of our Privacy Policy.

Subprocessors and data location

Every vendor that processes data on our behalf, its purpose, and its processing region are listed on our subprocessor list. Customers with a data processing agreement should read that page together with our Data Processing Addendum.

Security questionnaires and reviews

We do not currently hold a SOC 2 or ISO 27001 certification, and we will not claim one we do not have. Enterprise customers who need a security review or a completed questionnaire should reach us through Telegram.