Compliance
Responsible Disclosure Policy
eNeoteric welcomes security researchers who discover vulnerabilities in our systems. We are committed to working with the security community to verify and address reported vulnerabilities promptly and responsibly. This policy describes our disclosure guidelines and the protections we extend to good-faith researchers.
How to report
To report a security vulnerability in eNeoteric systems, email [email protected] with the following information:
- Description of the vulnerability — What you found, where, and how it works.
- Steps to reproduce — Clear steps that allow us to reproduce the issue reliably.
- Potential impact — Your assessment of what an attacker could achieve by exploiting this vulnerability.
- Proof of concept — Screenshots, videos, or code demonstrating the vulnerability (if safe to provide).
- Your contact information — So we can acknowledge your report and keep you updated.
You may encrypt your report using our PGP key, available at encse.com/.well-known/security.txt.
Our commitments to researchers
- Acknowledgement within 24 hours — We will confirm receipt of your report within 24 hours of submission.
- Status updates within 7 days — We will provide an initial assessment of the vulnerability's validity and severity within 7 business days.
- Remediation target of 30 days — We aim to remediate confirmed vulnerabilities within 30 days for critical/high severity, and 90 days for medium/low.
- Safe harbour — We will not pursue legal action against researchers who follow this policy and act in good faith. We will not refer compliant researchers to law enforcement.
- Credit — With your permission, we will acknowledge your contribution in our security acknowledgements page.
Scope and rules
In scope
encse.com and all subdomains, eNeoteric web applications and APIs, eNeoteric mobile applications, eNeoteric infrastructure directly supporting customer-facing services.
Out of scope
Third-party services integrated with eNeoteric systems (report to the respective vendor), social engineering attacks against employees, physical security attacks, denial of service attacks, and vulnerabilities in systems we do not own or control.
Rules of engagement
Do not access, modify, or delete customer data. Do not execute denial-of-service attacks. Do not use automated scanners at a rate that degrades service. Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it. Do not extort or demand payment for disclosure.
Frequently asked questions
- Will I be rewarded for reporting a vulnerability?
- eNeoteric does not currently operate a paid bug bounty programme. We offer public acknowledgement (with your permission) in our security hall of fame, and we are genuinely grateful for responsible disclosure. We are evaluating a formal bounty programme and will update this page if that changes.
- What if I accidentally accessed data I shouldn't have?
- Stop immediately and report it to [email protected]. Include what data you accessed, when, and how. We will not take legal action against researchers who access data incidentally while investigating a vulnerability, provided they report it promptly and do not retain or share the data.
- How long should I wait before publicly disclosing?
- We ask for 90 days from the date we confirm the vulnerability to remediate before public disclosure. If we are unable to remediate within 90 days, we will discuss an extension with you or coordinate a joint disclosure. We follow responsible disclosure norms consistent with Google Project Zero's standard.
- Can I test eNeoteric's systems with automated tools?
- Limited automated scanning of public-facing systems is acceptable at low request rates that do not degrade service. Do not run aggressive scans (Nuclei at high concurrency, masscan, etc.) against our infrastructure. If you need to use intensive automated tooling, contact us first at [email protected] to arrange a testing window.
Found a vulnerability? Report it.
[email protected]Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.