NAVRITU DIGITAL
VULNERABILITY DISCLOSURE POLICY
Effective Date: August 22, 2026
NavRitu Digital,(“NavRitu Digital,” “we,” “us,” or “our”), values the work of independent security researchers in helping us keep navritu.digital secure. This Vulnerability Disclosure Policy (“Policy”) describes how to report a security issue to us, what you can expect from us in return, and the rules that keep this process safe and lawful for everyone involved.
1. Our Commitment
If you report a security vulnerability to us in good faith and in accordance with this Policy, we commit to:
- Acknowledging receipt of your report within 5 business days
- Providing a point of contact for follow-up questions throughout the process
- Working to validate and remediate confirmed vulnerabilities in a reasonable timeframe based on severity
- Not pursuing or supporting legal action against researchers who follow this Policy in good faith
- Publicly acknowledging your contribution, if you would like credit, once the issue is resolved
2. Scope
|
In Scope |
navritu.digital and its subdomains |
|
Out of Scope |
Client-owned systems and deliverables (report these to the client directly); third-party services we use (Razorpay, Stripe, Google, hosting/cloud providers — report to that provider); social engineering or phishing of NavRitu Digital staff, contractors, or clients; physical security testing of any office or facility; denial-of-service (DoS/DDoS) testing; automated scanning that generates high volumes of traffic without prior coordination |
If you're not sure whether something is in scope, contact us before testing — we would rather answer a question than have someone test somewhere they shouldn't.
3. Safe Harbor
We consider security research conducted consistent with this Policy to be authorized. We will not initiate legal action against you for accidental, good-faith violations of this Policy, and we will make reasonable efforts to work with you to resolve any accidental scope issues before considering any escalation. This safe harbor applies only to testing performed strictly within the scope and rules described in this Policy, and does not extend to any third-party systems, services, or client-owned assets.
4. Rules of Engagement
When testing against navritu.digital and its subdomains, please:
- Make a good-faith effort to avoid privacy violations, degradation of service, and destruction or corruption of data
- Only interact with test accounts you own or have explicit permission to use
- Stop testing and notify us immediately if you access data that is clearly not yours (e.g., another user's personal information), and do not view, copy, store, or share that data beyond what is minimally necessary to prove the issue exists
- Avoid automated scanning configurations that could degrade the performance or availability of the site for other users
- Do not attempt social engineering, phishing, or physical access against our staff, contractors, or facilities
- Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly (see Section 6)
5. How to Report
Send reports to:
Email: connect@navritu.digital
To help us investigate quickly, please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, screenshots, or request/response data that demonstrates the issue (with sensitive data redacted where possible)
- The URL(s), endpoint(s), or component(s) affected
- Your preferred contact method and, if you'd like credit, the name/handle to use
6. Coordinated Disclosure
We ask that you give us a reasonable period to investigate and remediate a reported vulnerability — generally up to 90 days from our acknowledgment of your report, depending on severity and complexity — before disclosing it publicly. We will keep you informed of our progress and will work with you on an appropriate disclosure timeline, including earlier disclosure if a fix is deployed ahead of schedule.
7. Rewards & Recognition
NavRitu Digital does not currently operate a paid bug bounty program with fixed reward amounts. That said, we may offer a reward at our sole discretion for reports we consider particularly valuable, taking into account severity, quality of the report, and impact. Any such reward, if offered, is a discretionary gesture of appreciation, not a contractual entitlement, and is not guaranteed for any report.
8. Out-of-Scope Findings
The following are generally not actionable under this Policy unless you can demonstrate a realistic, meaningful security impact:
- Missing security headers or best-practice hardening suggestions without a demonstrated exploit
- Issues that require an unlikely degree of user interaction or a compromised device to exploit
- Reports generated purely by automated scanning tools without manual verification
- Rate-limiting or brute-force concerns on non-sensitive, non-authentication endpoints
- Vulnerabilities in software or services not owned or operated by NavRitu Digital
9. Legal
This Policy is not an invitation to actively probe systems beyond the scope defined above, nor does it authorize any activity against third-party services, client systems, or infrastructure not owned by NavRitu Digital. Nothing in this Policy waives our right to take appropriate action against activity that falls outside the scope or rules described here, including activity that is malicious, causes harm, or violates applicable law.
10. Changes to This Policy
We may revise this Policy from time to time to reflect changes in our scope, processes, or contact details. The Effective Date above reflects the most recent revision.
11. Contact Us
Security reports: connect@navritu.digital
General/legal inquiries: legal@navritu.digital