Skip to main content

Compliance is only the beginning—see how the SecureC ecosystem connects.Explore the platform

RESPONSIBLE DISCLOSURE

Found a weakness? We want to hear from you.

If you believe you have found a security vulnerability affecting SecureC, this page explains how to tell us, what we consider in scope, and how we will respond.

How to report

Email avijit.chakraborty@securecelullar.com with enough detail for us to reproduce the issue. Helpful reports usually include the affected URL or component, the steps you took, what you observed, and why you believe it is a security issue.

Please report privately and give us a reasonable opportunity to investigate and remediate before any public disclosure. If you are unsure whether something counts, send it anyway—we would rather triage a non-issue than miss a real one.

To be confirmedOur acknowledgement timeframe, and whether a PGP key is available for encrypted reports.

In scope

  • The SecureC public website and its web application
  • Authentication, session and access-control flaws
  • Injection, deserialization and similar server-side flaws
  • Sensitive information exposure
  • Business-logic flaws with a demonstrable security impact

To be confirmedThe definitive in-scope domain and subdomain list, once the production domain is confirmed.

Out of scope

  • Denial of service, volumetric or stress testing
  • Social engineering of our staff, customers or suppliers
  • Physical attacks against our premises or people
  • Automated scanner output with no demonstrated impact
  • Missing hardening headers with no exploitable consequence
  • Findings that require compromising another person's account
  • Third-party services we do not operate

What you can expect from us

  1. We acknowledge your report and confirm we are looking at it.
  2. We investigate, and we tell you what we concluded—including when we decide something is not a vulnerability, and why.
  3. We remediate what needs remediating, and we let you know when the fix is live.
  4. We will not pursue or support legal action against you for research conducted in good faith under this policy.

To be confirmedWhether public recognition is offered for valid reports. We do not operate a paid bounty programme, and this page will not imply one.

Related