Security

Responsible Disclosure Policy

How to report security vulnerabilities to Zurlux Technologies.

We build software that runs on production infrastructure at Indian banks. Security is not a marketing exercise for us. If you find a vulnerability, tell us — we will respond seriously.

How to report

Send security vulnerability reports to security@zurlux.com. If the report is sensitive, request our PGP public key at the same address and we will provide it for encrypted communication.

Report tosecurity@zurlux.com
AcknowledgementWithin 72 hours of receipt
Status updateWithin 7 days of acknowledgement
Resolution targetCritical: 48 hours · High: 7 days · Medium: 30 days
DisclosureCoordinated — we will agree timing with you

What to include in your report

Scope

The following are in scope for vulnerability reports:

The following are out of scope:

Our commitments to you

What we ask of you

Bug bounty

We do not currently operate a paid bug bounty programme. We recognise the work of security researchers with public credit (where desired) and, for significant findings, with direct acknowledgement from our founding team.

Report a vulnerability →