Trust Center

Transparency, security, and compliance at the core of Digital Anumati — under India's DPDP Act, 2023.

Responsible Disclosure Policy

Help Us Keep Digital Anumati Secure

We value the efforts of security researchers and the wider security community in helping us identify and responsibly disclose security vulnerabilities.

If you believe you have discovered a security issue affecting Digital Anumati, we encourage you to report it responsibly.

Scope

This policy applies to:

  • digitalanumati.com
  • Customer Portal
  • APIs
  • Consent Management Platform
  • Public web applications

How to Report

Please email: dpo@digitalanumati.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Screenshots (if available)
  • Proof of concept (if applicable)
  • Impact assessment

Our Commitment

Upon receiving a valid report, we will:

  • Acknowledge receipt within 2 business days
  • Investigate the issue
  • Prioritize remediation based on severity
  • Keep you informed during the process
  • Notify you once remediation has been completed (where appropriate)

Responsible Research Guidelines

We ask researchers to:

  • Avoid accessing customer data.
  • Do not modify or delete data.
  • Do not disrupt services.
  • Do not conduct denial-of-service attacks.
  • Avoid social engineering.
  • Respect customer privacy.

Safe Harbor

If your research:

  • Is conducted in good faith,
  • Follows this policy,
  • Avoids harming users or services,

Digital Anumati will not pursue legal action for your responsible security research.

Out of Scope

The following are generally out of scope:

  • Spam reports
  • Missing security headers with no exploitability
  • Self-XSS
  • Clickjacking without impact
  • Social engineering
  • Physical attacks
  • Third-party services outside our control