Skip to content

Responsible Disclosure Policy

eNeoteric welcomes security researchers who discover vulnerabilities in our systems. We are committed to working with the security community to verify and address reported vulnerabilities promptly and responsibly. This policy describes our disclosure guidelines and the protections we extend to good-faith researchers.

Report a Vulnerability Read Full VDP

How to report

To report a security vulnerability in eNeoteric systems, email [email protected] with the following information:

You may encrypt your report using our PGP key, available at encse.com/.well-known/security.txt.

Our commitments to researchers

Scope and rules

In scope

encse.com and all subdomains, eNeoteric web applications and APIs, eNeoteric mobile applications, eNeoteric infrastructure directly supporting customer-facing services.

Out of scope

Third-party services integrated with eNeoteric systems (report to the respective vendor), social engineering attacks against employees, physical security attacks, denial of service attacks, and vulnerabilities in systems we do not own or control.

Rules of engagement

Do not access, modify, or delete customer data. Do not execute denial-of-service attacks. Do not use automated scanners at a rate that degrades service. Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it. Do not extort or demand payment for disclosure.

Frequently asked questions

Will I be rewarded for reporting a vulnerability?
eNeoteric does not currently operate a paid bug bounty programme. We offer public acknowledgement (with your permission) in our security hall of fame, and we are genuinely grateful for responsible disclosure. We are evaluating a formal bounty programme and will update this page if that changes.
What if I accidentally accessed data I shouldn't have?
Stop immediately and report it to [email protected]. Include what data you accessed, when, and how. We will not take legal action against researchers who access data incidentally while investigating a vulnerability, provided they report it promptly and do not retain or share the data.
How long should I wait before publicly disclosing?
We ask for 90 days from the date we confirm the vulnerability to remediate before public disclosure. If we are unable to remediate within 90 days, we will discuss an extension with you or coordinate a joint disclosure. We follow responsible disclosure norms consistent with Google Project Zero's standard.
Can I test eNeoteric's systems with automated tools?
Limited automated scanning of public-facing systems is acceptable at low request rates that do not degrade service. Do not run aggressive scans (Nuclei at high concurrency, masscan, etc.) against our infrastructure. If you need to use intensive automated tooling, contact us first at [email protected] to arrange a testing window.

Found a vulnerability? Report it.

[email protected]

View Trust Centre  Full VDP

Request a Callback

Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.

💬 Chat on WhatsApp instead