Found something in our systems?
We build disclosure infrastructure, so it would be absurd not to accept reports about ourselves. Here is how to reach us and what we commit to in return.
How to report
Email info@shadowsecurity.in with "Security" in the subject line. Include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, and what you observed.
If you believe the issue is serious, say so in the first line. We would rather over-prioritise than miss something.
What we commit to
If you report in good faith under this policy:
- We will acknowledge your report.
- We will tell you whether we consider it valid, and why if we do not.
- We will keep you updated while we work on a fix.
- We will credit you if you would like to be credited, and stay quiet if you would not.
- We will not pursue legal action against you for research conducted in line with this policy.
What we ask
In return, we ask that you:
- Give us a reasonable opportunity to fix the issue before discussing it publicly.
- Do not access, modify or delete data belonging to anyone else.
- Do not degrade our services: no denial of service, no automated scanning that generates significant load.
- Do not use social engineering, phishing or physical intrusion against our people.
- Stop as soon as you have confirmed a vulnerability exists, rather than exploring how far it goes.
Scope
This policy covers systems Shadow Security operates, including this website. It does not extend to third-party services we use, or to our customers’ systems. If you find something in a customer’s system, report it to them, not to us.
We do not currently run a paid bug bounty. We are not going to imply otherwise to attract reports.
Suraksha VDP
Suraksha VDP is our forthcoming platform for exactly this kind of coordination between researchers and organisations. It is planned and not yet available; until it launches, the email address above is the route.