Responsible Disclosure Policy
Tatva Networks values the security research community. If you believe you have found a vulnerability in any Tatva Networks system, we want to hear from you and will work with you to resolve it quickly.
Scope
- tatvanetworks.com and its subdomains
- Public APIs operated by Tatva Networks
- Downloadable client software published by Tatva Networks
Third-party services (for example, our marketing analytics providers, hosted forms, or the underlying cloud infrastructure) are out of scope and should be reported to the respective vendor.
How to report
Please email security@tatvanetworks.com with:
- A clear description of the issue and its impact
- Step-by-step reproduction instructions
- Affected URL, endpoint, or component
- Any proof-of-concept material (please avoid destructive tests)
For sensitive reports you may request our PGP key in your first email and we will reply with a fingerprint before any details are shared.
Our commitments
- Acknowledge receipt within two business days
- Provide an initial triage response within seven business days
- Keep you informed as we investigate, remediate, and, where appropriate, deploy fixes
- Credit you publicly (with your permission) once a fix is released
Safe harbour
We will not pursue legal action against researchers who:
- Act in good faith and comply with this policy
- Avoid privacy violations, data destruction, and service disruption
- Only interact with accounts they own or have explicit permission to access
- Give us reasonable time to remediate before any public disclosure
Out of scope findings
- Missing security headers on non-sensitive pages without a demonstrated exploit
- Reports generated solely by automated scanners
- Social engineering, phishing, or physical attacks
- Denial-of-service or volumetric testing
- Rate-limit bypasses without meaningful business impact
Contact
Security team: security@tatvanetworks.com
General enquiries: info@tatvanetworks.com
