Home / Trust centre / Responsible disclosure
Found a problem with this site? Tell us.
If you have found a security issue affecting asveera.in, we would rather hear it from you than from somebody else. Here is how to report it and what we commit to in return.
Scope
This policy covers asveera.in and anything served from it. It does not cover our clients' systems. If you have found something in a client environment, do not test it further and do not contact that client. Write to us and we will route it properly.
How to report
Email contact@asveera.in with "security" in the subject line. Useful reports include:
- What you found, and where, with the exact URL
- How to reproduce it, step by step
- What an attacker could do with it
- Any screenshot or request log that helps us see it
- How you would like to be credited, or that you would prefer not to be
Please report in English. You do not need to prove impact by exploiting the issue, and we would prefer that you did not.
What we commit to
- Acknowledgement within 3 working days. From a person, not an autoresponder.
- An assessment within 10 working days, telling you whether we accept the finding and what we intend to do.
- Progress updates until it is closed, and confirmation when the fix is live.
- Credit on this page if you want it, once the issue is resolved.
- No legal action against you where you followed the guidelines below.
Research guidelines
Stay within these and you are acting in good faith as far as we are concerned.
- Do not access, modify or delete data that is not yours. If you reach personal data, stop and tell us immediately.
- Do not run denial of service tests, volumetric scans or anything that degrades the site for other people.
- Do not use social engineering, phishing or physical attacks against us or anyone connected to us.
- Do not publish the issue before we have fixed it. We will agree a disclosure date with you, and we will not drag it out.
- Use only your own test accounts and your own test data.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised, we will not pursue or support a claim against you, and we will say so publicly if a third party challenges your work on our behalf. If you are unsure whether something is in scope, ask us first and we will answer.
Out of scope
These are the reports we are likely to close without action, unless you can show a real attack path.
- Missing security headers with no demonstrated exploit
- Results from an automated scanner pasted without analysis
- Issues requiring an already compromised device or browser
- Reports about email configuration without a working spoofing proof
- Denial of service, rate limiting and volumetric findings
- Anything affecting an outdated browser no longer supported by its vendor
Rewards
We do not run a paid bug bounty. We would rather be honest about that than advertise a programme we cannot fund. What we offer is a fast, human response, public credit if you want it, and a genuine thank you.