Security
Vulnerability Disclosure
If you've found a security issue, please tell us privately. We'll acknowledge within 2 business days and keep you informed as we resolve it.
How to report
Email support@creativecyber.in with:
- What you found and where
- Steps to reproduce
- Your impact assessment
- A screenshot, request/response, or proof of concept
Please do not share the issue publicly until we've had a chance to address it.
Scope
In scope:
- creativecyber.in and all subdomains
- dpdp-assessment.creativecyber.in
- risksage.creativecyber.in
- api.risksage.creativecyber.in
- practitioner-toolkit.creativecyber.in
Out of scope:
- Third-party services (Zoho, AWS, Anthropic)
- Hosting infrastructure
- DoS / DDoS and load testing
- Social engineering or physical attacks
- Automated scanner output without demonstrated impact
Safe harbour
We will not pursue legal action under the IT Act 2000 against researchers who act in good faith — meaning you access only what is necessary to demonstrate the issue, do not exfiltrate or retain user data, and report to us before any public disclosure.
This covers only claims within CreativeCyber's control. It does not bind third parties or law enforcement. If another party initiates action, we will confirm to them that your research was conducted under this policy.
Recognition
We don't operate a paid bounty programme. Valid findings receive a private acknowledgement. For significant issues we'll provide a letter of recognition. We do not publish researcher names.
Customer incidents
If you're a customer reporting a data incident affecting your tenant, follow the breach notification process in your Data Processing Agreement — not this page.
Last updated: July 2026 · support@creativecyber.in