Responsible Disclosure Policy
1. Our commitment
Grids and Guides Technologies Private Limited takes the security of its systems, services, and clients seriously. We recognise that independent security researchers play an important role in the ongoing security of the internet. This policy sets out how you can report vulnerabilities to us, what you can expect in return, and the boundaries within which we ask you to work.
This policy is aligned to the coordinated vulnerability disclosure principles set out in ISO/IEC 29147.
2. How to report a vulnerability
If you believe you have discovered a security vulnerability in a Grids and Guides system, please report it to us at:
Email: [email protected] Please include "SECURITY DISCLOSURE" in the subject line so we can route your report to the security team quickly.
We ask that your report include:
- A clear description of the vulnerability.
- The specific URL, endpoint, product, or asset affected.
- Reproduction steps or a proof-of-concept that lets us confirm the issue.
- The potential impact, in your assessment.
- Any suggested remediation, if applicable.
- Your name or handle for acknowledgement (optional).
Please do not include sensitive personal data belonging to third parties in your report.
3. What you can expect from us
- We will acknowledge receipt of your report within three business days.
- We will provide an initial assessment and expected remediation timeline within ten business days.
- We will keep you reasonably informed of remediation progress.
- We will notify you when the issue is resolved.
- With your consent, we will publicly acknowledge your contribution in our security acknowledgements section once the issue is remediated.
4. Scope
The following are within scope for security research under this policy:
- The Grids and Guides website at gridsandguides.com and its sub-domains.
- Public-facing APIs owned and operated by Grids and Guides.
- Grids and Guides mobile applications, if any are published under our name.
The following are out of scope:
- Client production systems built or operated by Grids and Guides under a services engagement. Please contact the client directly, or contact us privately at [email protected] and we will facilitate.
- Third-party services, sub-processors, or vendors we use (please contact them directly through their own disclosure programmes).
- Systems, code, or infrastructure we do not own or operate.
- Physical security of our offices.
- Social engineering of Grids and Guides personnel, contractors, or clients.
- Denial-of-service (DoS/DDoS) testing, volumetric attacks, and stress testing.
- Automated scans that generate significant traffic or noise (please rate-limit yourself).
- Reports based purely on missing best-practice hardening headers, TLS configuration warnings from automated scanners, or theoretical issues without demonstrable impact.
5. Rules of engagement
We ask researchers to:
- Give us reasonable time to remediate before public disclosure. Our target is 90 days from initial report acknowledgement. If we need longer, we will explain why and coordinate a revised timeline with you.
- Access only the minimum amount of data necessary to demonstrate the vulnerability.
- Never intentionally access, modify, delete, or exfiltrate personal data belonging to other users. If you inadvertently encounter such data, stop, do not save it, and include the fact in your report.
- Never use the vulnerability to pivot into other systems.
- Never publicly disclose the vulnerability or share it with third parties before we have remediated it and, where relevant, coordinated a joint disclosure.
- Never demand payment, threaten disclosure, or engage in extortion. Doing so takes your report outside this policy.
- Comply with all applicable laws.
6. Safe harbour
Grids and Guides considers security research conducted in accordance with this policy to be authorised and beneficial. If you make a good-faith effort to comply with this policy, we will:
- Not initiate legal action against you for accessing, testing, or reporting vulnerabilities within scope.
- Consider your research to be lawful with respect to any applicable anti-hacking laws, including the Information Technology Act, 2000 (India) and the Computer Fraud and Abuse Act in the United States.
- Work with you if a third party (for example, a hosting provider) initiates action against your research activity, and share this policy on your behalf.
Safe harbour does not extend to:
- Actions that fall outside the scope of this policy.
- Research that violates the rules in Section 5.
- Actions that harm other users or damage systems.
If you are unsure whether a proposed action is within scope, please email us at [email protected] before proceeding.
7. Rewards
We currently operate a coordinated disclosure programme without monetary bounty. We recognise valid, high-impact reports with public acknowledgement (with your consent) and a written thank-you. If we introduce a paid bug bounty programme in future, we will publish its terms separately.
8. Security acknowledgements
We publicly acknowledge researchers who have responsibly reported valid security vulnerabilities to us, subject to their consent. The current list of acknowledgements is available at gridsandguides.com/security/acknowledgements.
9. Contact
- Security disclosures: [email protected] (subject line: SECURITY DISCLOSURE)
- General inquiries: [email protected]
For urgent security matters affecting production availability of a client engagement, please contact your named Grids and Guides partner directly, in addition to the security email above.

