HesperaLegal

Security

Last updated: 26 September 2026

This page describes how we protect the data entrusted to us, and how to tell us about a vulnerability.

1. How we protect data

1.1. Each client's data is kept apart from every other client's by the database itself, not by application code alone.

1.2. Access follows the principle of least privilege. Staff access is separate from client access, and two-factor authentication is mandatory for it. Two-factor authentication is available to every client.

1.3. Data is encrypted in transit, and our database and file storage encrypt it at rest. Credentials you give us for other services are encrypted again, with a key kept outside the database. The key with which we sign content credentials is held in a hardware security module.

1.4. Administrative actions by staff, including refused attempts, are written to a record that cannot be altered afterwards.

1.5. Our database, application servers and file storage are located in the European Economic Area. The full list of providers is at Sub-processors, and the measures we commit to are set out in our Data Processing Agreement.

2. Reporting a vulnerability

2.1. Write to security@hespera.ai. Describe the issue, the address or function affected, the steps to reproduce it, and what an attacker could achieve.

2.2. Do not include other people's personal data in your report. If your finding exposes such data, describe it without copying it.

3. What we ask of you

3.1. Test only against an account and a workspace that you created yourself.

3.2. Do not access, change or delete data that is not yours. If you reach such data, stop, and tell us.

3.3. Do not degrade the Service for others: no denial-of-service testing, no automated scanning at a volume that affects the Service, and no spam.

3.4. Do not use social engineering, phishing or physical access against us, our clients or our providers.

3.5. Give us reasonable time to fix the issue before you disclose it: until we tell you that it is fixed, or ninety days from your report, whichever comes first.

4. What we commit to

4.1. We acknowledge your report within five business days and keep you informed until the issue is resolved.

4.2. If you wish, we credit you once the issue is fixed. We do not currently pay rewards.

4.3. Research carried out in good faith and in accordance with this page is authorised, and this page constitutes our consent for the purposes of Article 5.1.6 of the Terms of Service. We will not take legal action against you for it.

5. Out of scope

5.1. Services run by our providers, such as payment and hosting providers: report those to the provider concerned.

5.2. Content that clients publish on their own storefronts: report it as described in the Acceptable Use Policy.

5.3. Findings without a demonstrated impact on security, such as the absence of a recommended header on a page that handles no data.

Back to hespera.ai