Legal
Responsible Disclosure Policy
Last updated: July 16, 2026
Security is our business, and we welcome the help of the research community in keeping RedStrike safe. This Vulnerability Disclosure Policy explains how to report a security issue to us, what you can expect in return, and the safe-harbor protections we extend to good-faith researchers.
Our commitment
At Encyfr Technologies Private Limited, we treat security as a continuous discipline, not a checkbox. We are committed to working openly and transparently with security researchers who report vulnerabilities responsibly. When you report an issue in good faith, we will investigate promptly, keep you informed, and give credit where you want it.
We ask that researchers give us a reasonable opportunity to remediate before disclosing publicly, avoid privacy violations and service disruption, and act in good faith. In return, we commit to responding quickly, being transparent about our timeline, and not pursuing legal action against good-faith research that follows this policy.
Scope
This policy covers vulnerabilities in the systems we operate, including:
- Our production web application and API.
- Our marketing website and related first-party subdomains.
- The infrastructure and integrations we directly control.
If you are unsure whether a target is in scope, ask us first at security@encyfr.ai. You can also learn more about how we secure the platform on our Trust & security page.
Safe harbor
We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorized. We will not initiate or support legal action against you for good-faith research that respects the rules below, and we will take steps to make it known that your actions were authorized if a third party raises a concern.
To qualify for safe harbor, you must make a good-faith effort to avoid privacy violations, data destruction, and service interruption; only interact with accounts you own or have explicit permission to access; and give us a reasonable time to remediate before any public disclosure. Safe harbor does not extend to actions that violate applicable law.
How to report
Send your report by email to security@encyfr.ai. If you need to share sensitive details, ask us for an encryption key and we will provide one. Please submit one issue per report so we can track and triage each finding cleanly.
Do not report security vulnerabilities through public channels, social media, or support tickets, and please do not disclose the issue publicly until we have confirmed it is resolved and coordinated a disclosure timeline with you.
What to include
To help us reproduce and fix the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it, including affected URLs or endpoints.
- Any proof-of-concept code, requests, or screenshots that demonstrate the issue.
- The environment, browser, or tooling you used.
- How you would like to be credited, if at all.
Our response process
We aim to be responsive and transparent throughout the process. Our target timelines are:
- Acknowledgment of your report within 2 business days.
- Triage and validation with an initial severity assessment within 5 business days.
- Status updates at reasonable intervals until the issue is resolved.
- Remediation prioritized by severity, with critical issues addressed as quickly as possible.
Once fixed, we will confirm the resolution with you and coordinate any public acknowledgment or disclosure.
Out of scope
Some findings generally do not qualify under this policy, including:
- Reports from automated scanners without a demonstrated, exploitable impact.
- Denial-of-service, volumetric, or resource-exhaustion attacks.
- Social engineering, phishing, or physical attacks against our staff or offices.
- Missing best-practice headers or configurations with no realistic security impact.
- Vulnerabilities in third-party services we do not control.
Importantly, do not attempt to test our customers’ systems or use the platform to scan assets you are not authorized to test — that is outside this policy and prohibited by our Terms of Service.
Rewards
We do not currently operate a paid bug-bounty program, but we deeply value the researchers who help us. With your permission, we are happy to recognize valid, previously unknown reports in a public acknowledgments list and to provide a reference for your responsible work.
If we introduce a formal rewards program in the future, we will describe its terms here. Any discretionary recognition we offer does not create an obligation or entitlement.
Legal
By submitting a report, you confirm that your research complied with this policy and applicable law, and that you will not publicly disclose the issue before we have resolved it and agreed on a disclosure timeline. This policy does not grant permission to act in any manner inconsistent with the law or that would cause us to be in breach of our own legal obligations.
We may update this policy from time to time; the version in effect when you submit a report governs it. Questions about this policy can be sent to security@encyfr.ai.
Questions about our policies?
Our team is happy to walk security and legal reviewers through how RedStrike handles data.