Security

Vulnerability Disclosure

If you've found a security issue, please tell us privately. We'll acknowledge within 2 business days and keep you informed as we resolve it.


How to report

Email support@creativecyber.in with:

  • What you found and where
  • Steps to reproduce
  • Your impact assessment
  • A screenshot, request/response, or proof of concept

Please do not share the issue publicly until we've had a chance to address it.

Scope

In scope:

  • creativecyber.in and all subdomains
  • dpdp-assessment.creativecyber.in
  • risksage.creativecyber.in
  • api.risksage.creativecyber.in
  • practitioner-toolkit.creativecyber.in

Out of scope:

  • Third-party services (Zoho, AWS, Anthropic)
  • Hosting infrastructure
  • DoS / DDoS and load testing
  • Social engineering or physical attacks
  • Automated scanner output without demonstrated impact

Safe harbour

We will not pursue legal action under the IT Act 2000 against researchers who act in good faith — meaning you access only what is necessary to demonstrate the issue, do not exfiltrate or retain user data, and report to us before any public disclosure.

This covers only claims within CreativeCyber's control. It does not bind third parties or law enforcement. If another party initiates action, we will confirm to them that your research was conducted under this policy.

Recognition

We don't operate a paid bounty programme. Valid findings receive a private acknowledgement. For significant issues we'll provide a letter of recognition. We do not publish researcher names.

Customer incidents

If you're a customer reporting a data incident affecting your tenant, follow the breach notification process in your Data Processing Agreement — not this page.

Last updated: July 2026 · support@creativecyber.in

    We use cookies and analytics (Google Analytics) to improve your experience. Under India's Digital Personal Data Protection Act, 2023, we require your consent before collecting any usage data. Privacy Policy