This article tells you how to reach HueChat quickly when you find a security weakness or suspect your account has been misused, and what HueChat does with your report.
Anyone, customer or not, can report a vulnerability.
Please do not test against other customers' accounts, do not download more data than you need to prove the issue, and do not run automated scanners against production. Use your own account, ideally a free trial created for the test.
HueChat acknowledges reports, investigates them, and fixes confirmed issues according to severity. We will tell you when the fix is live. HueChat does not currently run a paid bug bounty programme.
Use the same address and subject if you notice something wrong with your own account, for example:
While you wait for a reply, you can protect the account yourself:
Screenshot: The Active sessions list with a session being revoked.
Suspected incidents go straight to the HueChat operations team, which also receives alerts from the hourly host security watch and the database perimeter watch. The team contains the issue, preserves evidence and works out what data, if any, was affected.
If personal data you control is involved, HueChat notifies you without undue delay so you can meet your own obligations to your customers. Where HueChat itself is the controller, it notifies the competent authority within the period the law sets: 72 hours under GDPR, and the PDPL period for SDAIA in Saudi Arabia. Wider service incidents are posted on status.huechat.ai.
Never email a password, a full API key, a recovery code or a card number, even to HueChat. Support will never ask for them. The hc_ prefix of a key is enough to identify it.