Responsible Disclosure
EFFECTIVE · 1 APRIL 2026
We welcome reports from security researchers and members of the public who identify security issues affecting this website or the public-facing properties of the Shadgunya Group. This policy describes how to report an issue, what we commit to in return, and what is and is not in scope.
1. How to report
Send your report to spo@shadgunya.com. If you wish to encrypt your message, request our PGP key in your first email and we will reply with the current key fingerprint.
A useful report includes:
- A clear description of the issue and its potential impact.
- Step-by-step reproduction details, with timestamps where helpful.
- Affected URLs, endpoints, or assets.
- Any proof-of-concept material, scripts, or screenshots, where you can produce them safely.
- Your contact details and how you would like to be credited, if at all.
2. Our commitments to you
- We acknowledge receipt of your report within five working days.
- We provide an initial assessment within fifteen working days, including whether we consider the issue in or out of scope.
- We keep you informed of progress while remediation is under way, and we tell you when the issue is closed.
- We do not pursue civil action or notify law enforcement against researchers who act in good faith and follow this policy.
- If you wish to be credited, we acknowledge your contribution publicly with your consent. We do not currently operate a paid bug-bounty programme.
- We do not guarantee that all reported issues will be remediated or accepted as valid vulnerabilities, and remediation timelines may vary based on risk, complexity, and business priorities.
- Response timelines are indicative and may vary depending on the nature and complexity of the report.
- Submission of a report does not create any entitlement to compensation, reward, or reimbursement unless expressly agreed in writing.
3. Your commitments to us
- Make a good-faith effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or modification of data.
- Use only the minimum level of access necessary to demonstrate the issue. Stop testing once you have established that an issue exists.
- Do not access, store, transfer, or retain any personal or confidential data beyond what is strictly necessary to demonstrate the vulnerability and securely delete any such data immediately after testing.
- Do not conduct testing that generates excessive traffic or could reasonably be expected to impact the availability or performance of the Site.
- Give us a reasonable opportunity to remediate the issue before disclosing it publicly. Coordinated disclosure is the default; we will work with you to agree a reasonable coordinated disclosure timeline; however, public disclosure prior to remediation or without our consent may be considered a breach of this policy.
- Do not extort, threaten, or attempt to extract payment in exchange for withholding a report.
- Do not attempt to access or test systems, networks, or data beyond those explicitly in scope, including through lateral movement from an in-scope asset.
4. Scope
In scope.
- The Shadgunya Group corporate website at shadgunya.com and its subdomains.
- Any other property the Group expressly designates in writing as part of this programme.
Out of scope.
- Properties operated by the Group's operating companies (including pinacalabs.com and saptanglabs.com), which run their own programmes, please report issues to the relevant company directly.
- Third-party services that we rely on but do not operate (hosting, email, content delivery). Please report to the third party.
- Denial-of-service attacks, volumetric or otherwise.
- Social-engineering attacks against staff, contractors, or service providers.
- Physical security testing of any premises.
- Findings that depend on stolen credentials, unpatched user devices, or attacker-controlled hardware.
- Reports generated solely by automated scanners without manual analysis or demonstrated exploitability.
- Best-practice observations without a demonstrated security impact (for example, missing security headers, weak cipher suites that do not lead to a practical attack, or version disclosure).
5. Safe-harbour statement
Activities conducted in accordance with this policy are considered authorised. To the extent applicable laws permit, we will not pursue legal action against you for accessing the Site for the limited purpose of identifying and reporting security issues, provided you act in good faith, follow this policy, and do not exceed the scope above. This statement does not bind any third party or any law-enforcement agency.
Authorisation is limited to testing conducted against in-scope systems in a manner that does not intentionally degrade, disrupt, or impair the availability or performance of the Site.
6. Updates
This policy may be updated from time to time. The effective date at the top of the page reflects the current version. The latest version is always published at this URL.
7. Governing Law
This policy is governed by the laws of India, and any disputes arising in connection with it shall be subject to the exclusive jurisdiction of the courts of Chennai, India.