Responsible Disclosure Policy
1. Authorization Standard
RajSecure strictly operates under authorized security testing protocols. We do not provide unauthorized access, malicious hacking, credential theft, malware deployment, or unlawful testing services under any circumstances.
2. Vulnerability Reporting Procedure
If you believe you have identified a vulnerability related to RajSecure's digital infrastructure or public web presence, we encourage you to report it to us promptly:
- Email your findings to security@rajsecure.site.
- Include detailed steps to reproduce the vulnerability, request details, and proof of concept where applicable.
- Do not execute destructive payloads, data exfiltration, or denial-of-service attacks.
- Allow us reasonable time to investigate and remediate the issue prior to any public disclosure.
3. Client Security Engagement Boundaries
During client security assessments and penetration tests, RajSecure adheres strictly to agreed Rules of Engagement (RoE). Any testing beyond the predefined IP ranges, domain names, or application endpoints is explicitly prohibited.
4. Legal Safe Harbor
When security research is conducted in compliance with this policy and within authorized parameters, we consider such research to be authorized and will not initiate legal action against ethical security researchers.