We take the security of our systems seriously, and we value the work of security researchers. If you believe you've found a security vulnerability in a Yantra system, we'd like to hear from you and will work with you to resolve it.
Scope
In scope:
- yantratech.com and its subdomains (including www.yantratech.com)
- Yantra's apps, products and services
Out of scope:
- Third-party services we don't control (e.g. our email, hosting or marketing providers)
- Denial-of-service (DoS/DDoS) and volumetric attacks
- Social engineering, phishing, or physical attacks against staff or offices
- Reports from automated scanners without a demonstrated, exploitable impact
- Missing security headers, SPF/DMARC, or best-practice suggestions with no real-world impact
How to report
Email security@yantratech.com with:
- A clear description of the issue and where you found it
- Steps to reproduce, and a proof of concept if you have one
- The potential impact as you see it
Our commitment to you (safe harbour)
If you make a good-faith effort to comply with this policy, we will consider your research authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. To qualify, please:
- Act in good faith and avoid privacy violations, data destruction, and interruption or degradation of our services
- Only access or modify data that belongs to you, and only as far as needed to demonstrate the issue
- Give us a reasonable opportunity to fix the issue before disclosing it publicly
What to expect from us
- Acknowledgement — we aim to reply within 5 working days
- Validation and triage — we aim to assess valid reports within 10 working days
- Progress updates as we investigate, and a notification when the issue is resolved
- We currently do notoperate a paid bug bounty, but we're happy to credit researchers who report valid issues
Please do not
- Access, modify or delete data that isn't yours
- Degrade, disrupt or test the availability of our services (no DoS)
- Use social engineering, phishing or physical intrusion
- Publicly disclose the issue before we've had a reasonable chance to fix it
Reference
A machine-readable version of our security contact is published at https://www.yantratech.com/.well-known/security.txt.
Thank you for helping keep Yantra and our users safe.