We build software that runs on production infrastructure at Indian banks. Security is not a marketing exercise for us. If you find a vulnerability, tell us — we will respond seriously.
How to report
Send security vulnerability reports to security@zurlux.com. If the report is sensitive, request our PGP public key at the same address and we will provide it for encrypted communication.
| Report to | security@zurlux.com |
| Acknowledgement | Within 72 hours of receipt |
| Status update | Within 7 days of acknowledgement |
| Resolution target | Critical: 48 hours · High: 7 days · Medium: 30 days |
| Disclosure | Coordinated — we will agree timing with you |
What to include in your report
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof of concept if available)
- The affected product, component, or URL
- Your contact details for follow-up
Scope
The following are in scope for vulnerability reports:
- PatchMortem platform and API (app.patchmortem.com)
- PatchMortem agent software
- patchmortem.com and zurlux.com websites
- Authentication and authorisation mechanisms
- Data handling and encryption implementation
The following are out of scope:
- Denial of service attacks against our infrastructure
- Social engineering attacks against Zurlux staff
- Physical security of our premises
- Vulnerabilities in third-party software where we are not the maintainer
- Issues that require physical access to a user device
Our commitments to you
- We will acknowledge receipt of your report within 72 hours
- We will investigate and keep you informed of our progress
- We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy
- We will credit you in our disclosure (if you wish) after the vulnerability is resolved
- We will work with you to agree a disclosure timeline that protects users
What we ask of you
- Do not access, modify, or delete customer data — stop testing as soon as you identify a vulnerability
- Do not disclose the vulnerability publicly before we have resolved it and agreed a timeline with you
- Do not perform testing that could affect the availability of the service
- Act in good faith — we extend the same to you
Bug bounty
We do not currently operate a paid bug bounty programme. We recognise the work of security researchers with public credit (where desired) and, for significant findings, with direct acknowledgement from our founding team.