Security & Responsible Disclosure

Responsible Disclosure Policy

Indiconnect Paytech Private Limited is committed to maintaining the security of our systems and data. We value the security research community.

1. Purpose

Indiconnect Paytech Private Limited ("Indiconnect", "we", "our", or "us") is committed to maintaining the confidentiality, integrity, availability and security of its systems, platforms, services and data.

We acknowledge that independent security researchers and ethical hackers may identify security vulnerabilities that could assist in strengthening our security controls. This Responsible Disclosure Policy ("Policy") sets out the sole and exclusive framework under which such vulnerabilities may be responsibly disclosed to Indiconnect in a lawful, controlled and non-disruptive manner, and governs how Indiconnect will evaluate and respond to such disclosures.

2. Scope

This Policy applies to systems, applications, services, APIs, infrastructure and networks that are owned, operated or controlled by Indiconnect.

2.1. In-Scope

You are encouraged to report vulnerabilities or issues in the following:

  • Public-facing websites, web-applications and portals operated by Indiconnect (including but not limited to https://www.indiconnect.in).
  • APIs, integrations and back-end services made available by Indiconnect (where publicly accessible).
  • Authentication, session management, authorisation, business-logic controls, data encryption, sensitive data exposure, input-validation and common web-vulnerability classes such as:
    • Cross-site scripting (XSS)
    • SQL injection
    • Insecure direct object references (IDOR)
    • Server-side request forgery (SSRF)
    • Privilege escalation
    • Sensitive data exposure
    • Broken authentication or session controls

2.2. Out of Scope

The following are outside the scope of this Policy and should not be tested or reported under this Policy:

  • Physical attacks on Indiconnect's premises or infrastructure.
  • Social engineering or phishing attempts targeting Indiconnect personnel.
  • Denial-of-Service (DoS) or distributed DoS attacks performed against our systems.
  • Automated scanning tools, fuzz-testing or load-testing that may degrade or impair service availability.
  • Vulnerabilities arising solely from third-party systems, libraries or frameworks not under Indiconnect's control (unless exploit chains via Indiconnect systems can demonstrably be derived).
  • UI/UX bugs, spelling mistakes, styling issues, missing security headers or trivial mis-configurations that carry negligible risk or no meaningful proof-of-concept.
  • Issues in non-production, sandbox or test environments unless explicitly authorised in writing by Indiconnect.

If you are unsure about whether something is in-scope or out-of-scope, please contact us in advance.

3. Eligibility

To participate under this Policy you must meet the following conditions:

  • You are at least 18 years of age (or have the consent of a legal guardian).
  • You are not a current or former employee (including contractor or intern) of Indiconnect, nor engaged in any engagement with us that may pose a conflict of interest.
  • Your testing and reporting must comply with all applicable laws (including the Indian Information Technology Act, 2000, any amendments, rules/regulations, as well as other applicable jurisdictional laws) and must not violate any applicable contracts or terms of service.

4. How to Report a Vulnerability

Please submit your report to our dedicated email: grievance@indisign.co.in with the subject line: "Indiconnect Responsible Disclosure – [Short Title of Issue]"

Your report should include:

  • A clear, concise summary of the issue.
  • Step-by-step reproduction/investigation instructions.
  • Relevant URLs, API endpoints, parameters, or payloads.
  • Screenshots, logs or proof-of-concept (PoC) code, if available.
  • The potential impact and your assessment of severity (optional, but helpful).
  • Your contact details: full name, email address, phone number (optional), and affiliated organisation (if any).

Please do not publicly disclose the vulnerability (see Section 7 below) until we have had an opportunity to coordinate.

5. Our Commitment

Upon receiving a valid submission, Indiconnect will:

  • Acknowledge receipt of your report within five (5) business days.
  • Review and verify the issue; assess its severity, root cause and scope of impact.
  • Assign the issue for remediation in accordance with our internal prioritisation and timetable.
  • Work (if mutually agreed) with you to remediate the issue and coordinate disclosure.
  • At our sole discretion, we may provide recognition, public-acknowledgement (if you consent) or a reward (bug-bounty or other) for valid reports that lead to actionable improvements.
  • Maintain confidentiality of your identity and your report details unless disclosure is required by law or you consent to publication.

6. Rules of Engagement

By submitting a vulnerability under this Policy, you agree to comply with the following rules of engagement:

  • Only access systems, data or functionality that is in-scope and necessary to reproduce the vulnerability. Accessing, modifying, deleting or downloading data that does not belong to you is prohibited.
  • Do not disrupt, degrade or impair the performance, availability, reliability or integrity of Indiconnect's systems, services or infrastructure.
  • Do not attempt to exploit the vulnerability beyond proof-of-concept or to cause damage or leakage of sensitive information.
  • Do not target third-party systems, networks or services that are integrated or connected with our systems unless you have explicit prior written authorisation from Indiconnect.
  • Do not use brute force attacks, automated scanners, denial-of-service tools, fuzzers or load-generators unless you have prior written authorisation.
  • Do not withhold any information required by Indiconnect to reproduce or verify the issue. Providing incomplete or vague reports may result in disqualification.
  • Do not publicly disclose, share or otherwise publish the vulnerability, your findings or the remediation details without prior written agreement from Indiconnect.

Any violation of the rules of engagement may result in rejection of your report, termination of your eligibility under this Policy, and potential legal action, including but not limited to civil or criminal proceedings.

7. Public Disclosure & Coordination

We request that you refrain from publicly disclosing any vulnerability or related information until Indiconnect has had sufficient opportunity to review, remediate and coordinate an appropriate, safe disclosure. Public disclosure without our prior written consent may be deemed non-compliant with this Policy and may lead to us reserving all legal rights, including civil or criminal claims.

8. Legal Disclaimer

Participation in this disclosure programme does not grant you any right to act on our behalf, nor does it authorise you to conduct further testing beyond the scope defined in this Policy. Indiconnect reserves the right to modify, suspend or terminate this Policy at any time, for any reason, without prior notice. This Policy does not create any contract, partnership, or obligation to pay any reward, unless explicitly agreed in writing by Indiconnect.

9. Privacy & Data Handling

Any personal data provided by you in connection with your submission (such as your name, email address, IP address) will be collected solely for the purpose of managing our communications and handling the vulnerability report. We will treat your data confidentially and will not disclose your identity without your consent, unless required by applicable law or regulation. Any log data or system data you provide will be treated as confidential and subject to our data-protection and information-security policies.

10. Recognition and Rewards (Optional)

While we do not guarantee any bounty or reward, Indiconnect may at its sole discretion recognise contributors whose disclosures lead to genuine remediation and improved security. Recognition may include:

  • Public acknowledgement (with your consent).
  • Thank-you letter or certificate.
  • Nominal non-monetary token of appreciation.

Any determination of reward rests solely with Indiconnect and is subject to internal policy.

13. Contact Information

For queries, concerns or clarification about this Policy or your submission, please contact us at:

Email: grievance@indisign.co.in

Address: Office No.412, Tower - 2, WORLD TRADE CENTER, opp. Eon Free Zone Road, EON Free Zone, Kharadi, Pune, Maharashtra 411014

Contact No.: 920101013

Help Us Stay Secure

We appreciate the security research community's efforts in keeping our systems safe. If you've discovered a vulnerability, please report it responsibly.