Draft pending legal review
This document reflects how TrustShot is built and operated, and is being reviewed by counsel before general availability. Highlighted items are details still to be confirmed. Questions: contact@trustshot.in
1.How to report
Email contact@trustshot.in with the subject “Security report”. Include the affected URL or component, steps to reproduce, the impact you believe it has, and how to contact you. This address is also published at /.well-known/security.txt.
We acknowledge reports within two business days, keep you updated, and tell you when the issue is fixed.
2.Scope
In scope: trustshot.in, app.trustshot.in, and Trust Centers hosted on trustshot.in subdomains.
Out of scope: denial-of-service and volumetric testing; social engineering or phishing of staff or customers; physical attacks; attacks on third-party providers; reports from automated scanners without a demonstrated impact; missing best-practice headers with no exploit; and customers’ own domains unless the flaw is in TrustShot.
3.Rules of engagement
- Use only accounts you created yourself. Do not access, modify or delete other people’s data; if you encounter it, stop and tell us.
- Do not degrade the service or send more than a few requests per second.
- Give us reasonable time to fix the issue before disclosing it publicly, normally 90 days.
4.Safe harbour
If you act in good faith and follow this policy, we will not pursue legal action against you for your research and will regard it as authorised. This cannot bind third parties or authorities, and does not extend to activity outside this policy. We do not currently run a paid bounty programme, but we will credit you, with your permission.