Responsible Disclosure Policy
Help Us Keep Digital Anumati Secure
We value the efforts of security researchers and the wider security community in helping us identify and responsibly disclose security vulnerabilities.
If you believe you have discovered a security issue affecting Digital Anumati, we encourage you to report it responsibly.
Scope
This policy applies to:
- digitalanumati.com
- Customer Portal
- APIs
- Consent Management Platform
- Public web applications
How to Report
Please email: dpo@digitalanumati.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Screenshots (if available)
- Proof of concept (if applicable)
- Impact assessment
Our Commitment
Upon receiving a valid report, we will:
- Acknowledge receipt within 2 business days
- Investigate the issue
- Prioritize remediation based on severity
- Keep you informed during the process
- Notify you once remediation has been completed (where appropriate)
Responsible Research Guidelines
We ask researchers to:
- Avoid accessing customer data.
- Do not modify or delete data.
- Do not disrupt services.
- Do not conduct denial-of-service attacks.
- Avoid social engineering.
- Respect customer privacy.
Safe Harbor
If your research:
- Is conducted in good faith,
- Follows this policy,
- Avoids harming users or services,
Digital Anumati will not pursue legal action for your responsible security research.
Out of Scope
The following are generally out of scope:
- Spam reports
- Missing security headers with no exploitability
- Self-XSS
- Clickjacking without impact
- Social engineering
- Physical attacks
- Third-party services outside our control