IP
IndiaPulse

Security Policy

Responsible disclosure guidance, updated 26 August 2026

Report a vulnerability

Email security@indiapulse.org with the affected URL or component, impact, reproducible steps, and any supporting request or response details. Remove credentials, personal data, and market-sensitive information from the report. We aim to acknowledge valid reports within two business days.

Good-faith research

Use only accounts and data you own or have explicit permission to test. Stop if you encounter personal data, gain unintended access, or could affect availability. Do not use denial of service, social engineering, malware, spam, destructive actions, or automated testing that materially loads production. Allow reasonable time to remediate before public disclosure.

IndiaPulse will not pursue legal action for accidental, good-faith research that follows this policy, avoids harm, and complies with applicable law. This is not authorization to access third-party systems or data.

Scope and rewards

The primary scope is indiapulse.org and services demonstrably controlled by IndiaPulse. Findings limited to missing best-practice headers, self-XSS, version disclosure without an exploit, or automated scanner output without a reproducible impact may not require a response. IndiaPulse does not currently operate a paid bug-bounty program.

Security Policy | IndiaPulse