Security

Vulnerability Disclosure Policy

Last updated: 26 June 2026

We take the security of our systems seriously. This page tells you how to report a vulnerability, what we commit to in return, and what we ask of you while we work together.

Quick links · /.well-known/security.txt · security@sriinfoit.com

1. Scope

The following systems are in scope for our vulnerability disclosure programme:

The following are out of scope — please do not test these:

2. How to report

Send an email to security@sriinfoit.com. Please include:

For sensitive reports, request our PGP key by emailing security@sriinfoit.com and we'll send it to you directly.

3. What we commit to

4. What we ask of you

5. Severity guidance

We use roughly the following internal severity buckets to set remediation timelines. These are not contractual; they help us prioritise.

SeverityTypical examplesTarget remediation
CriticalAuthentication bypass, RCE, full data exposureWithin 7 days
HighPrivilege escalation, stored XSS in authenticated context, SSRF reaching internal hostsWithin 30 days
MediumReflected XSS, CSRF on non-critical actions, info-disclosure of non-sensitive dataWithin 60 days
LowMinor info disclosure, missing security headers without exploit pathWithin 90 days

6. Out-of-scope issue types

The following issues are typically not eligible. Reporting them is fine; we just may not act on them as security issues:

7. Acknowledgements

Researchers who have reported valid issues to us will be listed here, with their consent, after their issues are resolved. (No issues to acknowledge yet — if you're the first, you'll get the top spot.)

8. Contact

Security Team — SRI INFOIT
Email: security@sriinfoit.com
PGP: available on request via email
For legal escalations, see the contact info on our Privacy Policy.