Security

Vulnerability Disclosure Policy

We take the security of our systems seriously. This page tells you how to report a vulnerability, what we commit to in return, and what we ask of you while we work together.

Quick links · /.well-known/security.txt · security@sriinfoit.com

1. Scope

The following systems are in scope for our vulnerability disclosure programme:

The following are out of scope — please do not test these:

2. How to report

Send an email to security@sriinfoit.com. Please include:

For sensitive reports, our PGP key is published at /.well-known/security-pgp.asc. Encrypt to that key if you'd prefer.

3. What we commit to

4. What we ask of you

5. Severity guidance

We use roughly the following internal severity buckets to set remediation timelines. These are not contractual; they help us prioritise.

SeverityTypical examplesTarget remediation
CriticalAuthentication bypass, RCE, full data exposureWithin 7 days
HighPrivilege escalation, stored XSS in authenticated context, SSRF reaching internal hostsWithin 30 days
MediumReflected XSS, CSRF on non-critical actions, info-disclosure of non-sensitive dataWithin 60 days
LowMinor info disclosure, missing security headers without exploit pathWithin 90 days

6. Out-of-scope issue types

The following issues are typically not eligible. Reporting them is fine; we just may not act on them as security issues:

7. Acknowledgements

Researchers who have reported valid issues to us will be listed here, with their consent, after their issues are resolved. (No issues to acknowledge yet at the time of v7.1 launch — if you're the first, you'll get the top spot.)

8. Contact

Security Team — SRI INFOIT
Email: security@sriinfoit.com
PGP: /.well-known/security-pgp.asc
For legal escalations, see the contact info on our Privacy Policy.