Compliance
Vulnerability Disclosure Policy
This Vulnerability Disclosure Policy (VDP) formalises eNeoteric's commitment to the security research community. It defines the scope of systems covered, the rules of engagement, our response timelines, and the safe harbour protections we extend to researchers acting in good faith. Version 1.0 — effective 1 January 2026.
1. Scope
1.1 In-scope systems
The following systems are in scope for vulnerability disclosure: www.encse.com and all subdomains (*.encse.com), eNeoteric customer portal applications, eNeoteric mobile applications (iOS and Android), APIs documented at api.encse.com, eNeoteric internal systems accessible from the internet.
1.2 Out-of-scope systems
Third-party SaaS tools used by eNeoteric (report to the relevant vendor), customer environments managed by eNeoteric (contact the respective customer), social engineering or physical security attacks, and systems not listed as in-scope above.
2. Severity classification
- Critical (CVSS 9.0–10.0) — Remote code execution, authentication bypass leading to full system compromise, mass data exfiltration. Remediation target: 7 days.
- High (CVSS 7.0–8.9) — SQL injection, SSRF, privilege escalation, significant data exposure. Remediation target: 30 days.
- Medium (CVSS 4.0–6.9) — XSS, CSRF, information disclosure. Remediation target: 60 days.
- Low (CVSS 0.1–3.9) — Best-practice issues, minor information leakage. Remediation target: 90 days.
3. Safe harbour
eNeoteric authorises security research conducted in accordance with this policy. We consider activities conducted under this policy to constitute "authorised" conduct. We will not initiate legal action under the IT Act 2000, Computer Fraud and Abuse Act, or equivalent legislation against researchers who:
- Notify us promptly upon discovery and do not exploit the vulnerability further than necessary to demonstrate impact.
- Do not retain, share, or monetise any data accessed incidentally during testing.
- Allow us the agreed remediation period before public disclosure.
- Do not conduct testing that degrades service availability for other users.
4. Response timeline
- Acknowledgement — Within 24 hours of report receipt.
- Initial triage — Within 5 business days: confirmation of scope, initial severity assessment.
- Status update — Weekly updates until resolution for Critical/High; bi-weekly for Medium/Low.
- Remediation — Per severity classification in Section 2 above.
- Disclosure coordination — We coordinate public disclosure timing with the researcher, targeting 30–90 days post-report.
Frequently asked questions
- Does this policy apply to vulnerabilities in customer environments eNeoteric manages?
- No. If you discover a vulnerability in a system managed by eNeoteric on behalf of a customer, please contact that customer directly. eNeoteric-managed infrastructure is in scope; customer workloads are not.
- What encryption should I use when submitting my report?
- You can encrypt reports using our PGP key available at encse.com/.well-known/security.txt. For reports that do not require encryption, a plain-text email to [email protected] is sufficient. Do not send vulnerability details via LinkedIn messages or other social media channels.
- Will eNeoteric notify me when the vulnerability is fixed?
- Yes. We notify the reporting researcher when the vulnerability has been remediated and provide details of the fix so you can verify the resolution. If you would like to re-test the fix, we will coordinate access with you.
- Can I use this finding in my own research publications?
- Yes, after the coordinated disclosure period. We ask that you allow us the agreed remediation window before publishing, and that any publication is factually accurate and does not include details that would enable exploitation by third parties before our customers have had the opportunity to patch.
Discovered a vulnerability?
Email [email protected]Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.