Coordinated vulnerability disclosure policy.
This policy governs how CyVigilant identifies, validates, and discloses security vulnerabilities found in third-party systems during its research — and how others may report vulnerabilities to us. It exists to protect affected organisations and their users, to resolve real risk quickly, and to do so lawfully and in good faith.
Last updated · June 2026
Purpose and Commitment
CyVigilant Technologies Private Limited ("CyVigilant", "we", "us", or "our") is a cybersecurity research and threat-hunting firm. In the course of our work we may discover security weaknesses in systems that are reachable from the public internet. Where we do, we are committed to disclosing them responsibly — privately, promptly, and constructively — so they can be remediated before they are abused.
We treat every disclosure as a partnership with the affected organisation. Our objective is never publicity, pressure, or commercial gain; it is the timely remediation of genuine risk and the protection of the people whose data depends on it. Disclosure is offered without precondition and is never contingent on the purchase of any CyVigilant service.
Scope
This policy applies to vulnerabilities identified by CyVigilant in the systems, applications, APIs, cloud infrastructure, and internet-facing assets of organisations with which we engage through responsible disclosure. It also describes how third parties may report vulnerabilities affecting CyVigilant.
Our research is limited to what is observable from publicly reachable surfaces or to activity within the bounds of an authorised engagement. We do not test systems we are not authorised to assess beyond the minimum necessary to confirm that a vulnerability exists and is exploitable. Social engineering of staff, physical intrusion, denial-of-service, and any activity that degrades or disrupts a live service are out of scope and are never performed.
Guiding Principles
Good faith — we act to protect, never to extort, embarrass, or profit from exposure. Minimise harm — we access the least data required to demonstrate impact and stop the moment exploitability is confirmed. Confidentiality first — findings are held in strict confidence and shared only with the affected organisation through a secure channel. Lawful conduct — our research is conducted within the bounds of applicable law and recognised disclosure norms.
Our Coordinated Disclosure Process
We follow a structured, time-bound process. The timelines below are guidelines: where a recipient engages constructively we are flexible, and where an exposure is active and severe we move faster.
Discovery and validation (Day 0). Our research team confirms exploitability and scope using the minimum interaction necessary. No destructive testing is performed and no production data is altered.
Notification (within 72 hours of validation). We notify the affected organisation through a verified security contact and request acknowledgement of receipt.
Secure handoff (on acknowledgement). A full technical report — including reproducible proof-of-concept steps, affected endpoints, and remediation guidance — is shared over an encrypted channel of the recipient’s choosing.
Remediation window (up to 90 days). We support remediation and re-validate fixes on request. This window may be extended by mutual agreement where complexity warrants it.
Coordinated public disclosure (after remediation, or 90 days). Any public reference is coordinated, sanitised, and never includes customer data or exploit detail that would enable harm. Agreed embargoes are honoured.
What Affected Organisations Can Expect
When CyVigilant contacts you about a finding, our researchers commit to the following: we will not publicly disclose, sell, or trade any finding or associated data; we will not access, copy, modify, or retain data beyond what is strictly necessary to evidence the issue, and we securely destroy any such evidence once the matter is resolved; we will provide clear, reproducible technical detail and practical remediation guidance; we will respect a reasonable remediation window and coordinate any public reference with you; and we will never demand payment in exchange for withholding a finding.
Data Handling and Confidentiality
Evidence is collected solely to confirm and communicate risk. Sensitive material is minimised, encrypted in transit and at rest, access-controlled to the engaged research team, and destroyed on resolution. We do not exfiltrate datasets, and we redact or sanitise personal data in any report wherever it is not essential to demonstrating the vulnerability.
Legal and Regulatory Alignment
CyVigilant conducts disclosure in alignment with India’s applicable legal and regulatory framework, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, RBI information-security guidance for regulated entities, and CERT-In directions on incident reporting. Where a finding implicates a recipient’s own statutory obligations, we will say so plainly and support timely, compliant handling — but the determination and discharge of those obligations rests with the affected organisation.
Reporting a Vulnerability to CyVigilant
We welcome reports about our own products and infrastructure. If you believe you have found a vulnerability affecting CyVigilant, please email security@cyvigilant.com with a detailed description and reproduction steps. We will acknowledge your report within 48 hours, keep you updated on remediation, and — with your consent — credit you once the issue is resolved.
Safe harbour. Provided you act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to remediate before any public discussion, CyVigilant will not pursue or support legal action against you for your research.
Contact
For any matter relating to this policy, or to arrange a secure technical handoff, contact our disclosure team at disclosure@cyvigilant.com. To report an issue in CyVigilant’s own systems, contact security@cyvigilant.com. We can exchange material over PGP-encrypted email or a secure channel of your choosing. A machine-readable summary is published at /.well-known/security.txt.
