security-policy
🛡️ RFC 9116 COMPLIANT
Vulnerability Disclosure Policy
Version 2.0 • Providing white-hat security researchers and ethical engineers a safe harbor to report vulnerabilities.
🕊️ Safe Harbor Commitment: Researchers acting in good faith, following this policy, and avoiding harm to users or services will be treated as authorized security researchers while issues are investigated. Unauthorized access, data theft, privacy violations, or service disruptions are strictly prohibited.
Contact Gateways
Please submit security feedback directly through our verified operational vectors:
SLA Target Response
72 Hours
Initial Response Window
Status Updates: Transparent reporting progress milestones will be provided throughout our active investigation whenever technically possible.
Reportable (In-Scope)
We prioritize the remediation of the following systematic flaws within https://www.pravinzende.co.in/:
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection Flaws
- Remote Code Execution (RCE)
- Authentication Bypass Flaws
- Authorization and Privilege Escalation
- Session Management Problems
- Server Misconfiguration Errors
- Sensitive Information Disclosure
- API Security & Header Weaknesses
- Third-Party Dependency Vulnerabilities
Prohibited (Out of Scope)
The following methods are strictly disruptive and violate safe harbor parameters:
- Denial of Service (DoS / DDoS) tests.
- Phishing, social engineering, or scam frames.
- Accessing, copying, or modifying native user data.
- Spamming contact forms, emails, or comments loops.
- Attacking integrated external or third-party entities.
- Executing destructive or data-wiping security tests.
Target Infrastructure Framework
Platform: Google Blogger
Hosting: Google Infrastructure
SSL State: Strict HTTPS Active
Data Layer: JSON-LD Graphs
Defenses: Security Headers Engaged
Performance: Core Web Vitals Optimized
Canonical Registries
RFC 9116 Paths:
/.well-known/security.txt
/security.txt
Preferred Languages:
Preferred Languages:
English (en), Marathi (mr), Hindi (hi)