Responsible Disclosure
Effective date: 29 July 2026 · CyberDudeBivash Pvt. Ltd. ("we", "us") · blog.cyberdudebivash.in
1. Scope
This policy covers blog.cyberdudebivash.in and the API endpoints it exposes (/api/*). If you've found a security issue in a different CYBERDUDEBIVASH property, please still report it here — we'll route it to the right place.
2. How to report
Email bivash@cyberdudebivash.com with a description of the issue, steps to reproduce, and any proof-of-concept material. Please do not include real customer data in your report.
3. What to expect
We aim to acknowledge new reports as quickly as we can and will keep you updated as we investigate. We do not currently offer a paid bug bounty program, but we credit and thank researchers who report responsibly, with your permission.
4. Safe harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: avoid privacy violations, data destruction, and service disruption, and give us a reasonable opportunity to investigate and remediate before any public disclosure.
5. Out of scope
- Denial-of-service testing against production
- Social engineering against our team, customers, or partners
- Automated scanning that generates significant load
- Reports without a working proof of concept
6. Contact
CyberDudeBivash Pvt. Ltd. · bivash@cyberdudebivash.com · security.txt