Purpose
Security researchers, customers, partners, vendors and members of the public may report a suspected vulnerability. A vulnerability is an unintended weakness or exposure that could reasonably compromise the confidentiality, integrity or availability of an in-scope system or its data.
This policy explains which systems and research methods are authorised, how to submit a useful report, how we handle it, and the conditions for coordinated public disclosure. It is not permission to access data, accounts or systems beyond what is necessary to demonstrate a finding safely.
Scope
In scope
https://avyntis.in.netand its first-party APIs.- The current supported release of the Avyntis application supplied by us.
- Public assets that we own and operate and that this policy expressly identifies.
- Authentication, authorisation, tenant isolation, data exposure and security-control weaknesses affecting those systems.
Out of scope
- Other
avyntis.in.netsubdomains unless their own policy includes them. - Customer-hosted infrastructure, customer data or customer domains not operated by us.
- Third-party services, integrations, open-source projects or vendors that we do not control.
- Unsupported, end-of-life or locally modified releases unless the issue also affects a supported release.
- Findings based only on automated scanner output without evidence of a security impact.
If you are uncertain whether an asset or method is in scope, contact us before testing. We may add or remove assets as our systems change; the version published here at the time of testing applies.
Research rules
When testing an in-scope system, you must:
- use accounts and data that you own or have explicit permission to use;
- make a reasonable effort to avoid privacy violations, service degradation and data loss;
- limit requests, records and proof-of-concept activity to what is necessary to confirm the issue;
- stop if testing causes instability, reaches another person's data, or could cause material harm;
- protect vulnerability details and any evidence from unauthorised access; and
- coordinate disclosure with our security team as described below.
The following activities are not authorised:
- denial-of-service, load, stress or resource-exhaustion testing;
- social engineering, phishing, spam, harassment or physical intrusion;
- credential stuffing, password spraying or brute-force attacks;
- malware, ransomware, destructive payloads, persistence or command-and-control activity;
- changing, deleting, downloading in bulk or publicly exposing data;
- demanding payment or threatening disclosure, service disruption or data release.
How to report a vulnerability
Email the security team
security@avyntis.in.netUse the subject “Security vulnerability report” and do not send passwords, private keys, access tokens or unnecessary personal data in ordinary email.
A useful report includes:
- the affected URL, API, version, feature or asset;
- the vulnerability type and its realistic security impact;
- clear, reproducible steps and the date and time of testing;
- a minimal proof of concept, screenshots or redacted request/response details;
- suggested remediation, if known; and
- your preferred name, contact method and whether you would like public credit.
What happens after a report
- 1
Acknowledgement
We will aim to confirm receipt promptly and may request missing details.
- 2
Triage
We reproduce the issue, establish scope and severity, remove duplicates and identify the responsible owner.
- 3
Coordination
We keep the reporter informed when practical and may ask for retesting or clarification.
- 4
Remediation
We prioritise a fix or mitigation according to verified risk, affected customers and operational constraints.
- 5
Closure
We confirm the outcome we can disclose and, when appropriate, coordinate an advisory or public credit.
Coordinated disclosure
Please keep the report and vulnerability confidential until we confirm remediation or agree on a disclosure date. We will not unreasonably delay a good-faith disclosure.
Recognition and bounty status
This is a vulnerability disclosure programme, not a bug bounty. Submission does not create a right to payment, reward, employment or reimbursement. We may offer public acknowledgement for a distinct, validated report if the researcher requests it and disclosure is safe.
Questions
Questions about scope, safe testing or an existing report should be sent to security@avyntis.in.net.