Responsible disclosure
If you have found a security issue in this website or in anything we operate, we would rather hear it from you than from someone else.
How to report
Email founder@neuralchetna.com with enough detail to reproduce the issue: the URL or endpoint, the steps, and what you observed. If the finding is sensitive, say so and we will arrange an encrypted channel.
What we commit to
- We acknowledge reports within three working days.
- We give you an assessment and a remediation timeline within ten working days.
- We will not pursue legal action against good-faith research that follows this policy.
- We will credit you when the issue is resolved, if you would like us to.
What we ask
- Give us a reasonable period to fix the issue before disclosing it publicly.
- Do not access, modify or delete data that is not yours.
- Do not run denial-of-service tests, automated scanning at damaging volume, social engineering, or physical attacks against our staff or providers.
- Use only test data in any proof of concept.
Out of scope
- Missing security headers with no demonstrated impact.
- Reports generated solely by an automated scanner without a working proof of concept.
- Issues in third-party services we do not control.
- Social engineering of our people or our providers.
We do not currently run a paid bug bounty. That does not diminish our appreciation for a well-written report.
