Responsible Security Disclosure.
How to report a security issue to SMMARUN, what we cover under safe harbour, and what you can expect from us in return.
What this page is
This is SMMARUN's coordinated vulnerability disclosure policy. We invite good-faith security researchers to report vulnerabilities in our web properties, and we set out here what is in scope, what is out of scope, and the protections we extend to anyone who reports an issue in good faith.
We treat security disclosures seriously. We thank researchers who help us protect the people who trust us with their data.
Scope (in)
The following SMMARUN-controlled web properties and surfaces are in scope:
- The production website at
smmarun.aiand any sub-domains we operate. - The preview deployment at
smmarun-site.vercel.app. - The form-submission endpoints used for Begin a conversation, Library gated-content requests, and any other form on the public site.
- The cookie-consent and analytics-consent infrastructure that records and enforces visitor consent choices.
Scope (out)
The following are not in scope. Please report any issues you find in these to the relevant vendor directly:
- Third-party services we use. Microsoft Dynamics 365, Google Analytics, and Vercel hosting infrastructure are operated by those vendors. Report issues to their respective security teams.
- Physical security. Our offices, devices, and physical premises are not in scope for this policy.
- Social engineering of SMMARUN staff, partners, or contractors. Phishing, vishing, pretexting, and similar techniques targeted at people are not authorised under this policy.
- Denial-of-service testing. Active denial-of-service or volumetric testing is not authorised. See the next section.
Safe harbour
SMMARUN will not pursue civil or criminal action against a researcher who, in our reasonable judgement:
- Acts in good faith to identify and report a security issue.
- Does not access or modify data beyond what is strictly necessary to demonstrate the issue.
- Does not exfiltrate, retain, or share personal data belonging to SMMARUN, our staff, our partners, our clients, or our visitors.
- Does not disclose the issue publicly before SMMARUN has had a reasonable opportunity to remediate. Our default coordination window is 90 calendar days from acknowledgement, or another period agreed in writing between you and us.
- Does not breach Indian law or the law of the researcher's home jurisdiction in the course of the research.
If you act within these limits and we later find ourselves in disagreement about whether you did, we will engage with you in good faith before taking any other step.
Out of safe harbour
The following actions fall outside safe harbour and may be referred to law enforcement or pursued through other lawful means:
- Attempts to access user data beyond the minimum required to demonstrate the vulnerability.
- Denial-of-service attacks, volumetric stress tests, or resource-exhaustion attacks against production systems.
- Spam, mass mailing, or other abuse of our forms and endpoints.
- Physical intrusion or attempted intrusion into SMMARUN premises.
- Phishing, vishing, or other social-engineering attempts targeted at SMMARUN staff, partners, or contractors.
- Testing against third-party vendors named in the out-of-scope section above. Direct that work to those vendors under their own policies.
How to report
Send the report by email to security@smmarun.ai with the subject Security disclosure. If the security@ alias has not yet been provisioned at the time you write, please use hello@smmarun.ai with the same subject; we will route the report internally.
Please include, where you can:
- The affected URL or endpoint.
- Clear reproduction steps a member of our team can follow.
- A description of the impact (what an attacker could do with this issue).
- Your preferred contact method and, if you would like to be credited, the name or handle you would like used.
PGP encryption is available on request. Email us first and we will exchange keys.
Our commitments to you
- Acknowledgement within 72 hours of your initial report.
- Triage within 7 calendar days of acknowledgement: we will confirm whether we can reproduce the issue and our initial severity assessment.
- Remediation timeline communicated within 30 days of triage: we will tell you when we expect to ship a fix.
- Credit on request. With your consent, we will name you in our acknowledgements page after a fix is deployed. You may request to remain anonymous.
- No cash bug bounty at this stage. We do not currently offer monetary rewards. We may introduce a paid programme in future.
CERT-In notification
For security incidents that meet the reporting threshold under the Directions of the Indian Computer Emergency Response Team (CERT-In) of 28 April 2022, SMMARUN reports to CERT-In within the prescribed 6-hour window. Your report helps us meet that obligation; we will not name you to CERT-In without your consent.
Standards alignment
This policy and the internal handling process behind it are aligned to:
- ISO/IEC 29147:2018 — Information technology, Security techniques, Vulnerability disclosure.
- ISO/IEC 30111:2019 — Information technology, Security techniques, Vulnerability handling processes.
We use these standards as guidance for how reports are received, triaged, communicated, and resolved internally.
Changes to this policy
We may update this policy from time to time. Material changes will be flagged at the top of this page on the next visit, and the Last reviewed date below will be updated. Previous versions are available on request.