security-policy
Vulnerability Disclosure Policy
Version 2.0 • Providing white-hat security researchers and ethical engineers a safe harbor to report vulnerabilities.
Contact Gateways
Please submit security feedback directly through our verified operational vectors:
SLA Target Response
Status Updates: Transparent reporting progress milestones will be provided throughout our active investigation whenever technically possible.
Reportable (In-Scope)
We prioritize the remediation of the following systematic flaws within https://www.pravinzende.co.in/:
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection Flaws
- Remote Code Execution (RCE)
- Authentication Bypass Flaws
- Authorization and Privilege Escalation
- Session Management Problems
- Server Misconfiguration Errors
- Sensitive Information Disclosure
- API Security & Header Weaknesses
- Third-Party Dependency Vulnerabilities
Prohibited (Out of Scope)
The following methods are strictly disruptive and violate safe harbor parameters:
- Denial of Service (DoS / DDoS) tests.
- Phishing, social engineering, or scam frames.
- Accessing, copying, or modifying native user data.
- Spamming contact forms, emails, or comments loops.
- Attacking integrated external or third-party entities.
- Executing destructive or data-wiping security tests.
Target Infrastructure Framework
Canonical Registries
Preferred Languages: