Skip to content
DPDP
Draft outline·counsel review pending

Responsible Disclosure

How to report a security vulnerability to us safely, what we commit to in return, and what is out of scope.

Sections
4Sections
Always
PublicAlways
Governing law
IndiaGoverning law

Draft outline — not yet legally binding. This page lists the sections this document must contain. The operative text needs your legal entity name, registered address and Grievance Officer details, and must be reviewed by counsel before publication. Send us those details and we will complete it.

1. How to report

The security contact address and the PGP key for encrypted reports.

2. Our commitment

Acknowledgement timeline, status updates, and no legal action for good-faith research.

3. Scope

Which domains and systems are in scope, and which are explicitly excluded.

4. Out of scope

Report types we do not act on, stated plainly so nobody wastes their time.

Questions about this document? Write to [email protected].