CCYINSOLUTIONS
PrivacyTermsResponsible disclosure
Back to website ↗

SECURITY RESEARCH · GOOD FAITH · COORDINATION

Responsible Disclosure

We welcome careful, good-faith security research that helps protect CYIN users. This policy explains how to test safely and report a suspected vulnerability.

Effective 18 July 2026CYIN Solutions Pvt. Ltd.India
DOCUMENT CENTREPrivacy PolicyTerms of UseResponsible DisclosureQuestions about these documents?admin@cyinsolutions.in
Found a security issue?

Email admin@cyinsolutions.in with the subject “SECURITY DISCLOSURE: [short title]”. Please do not send sensitive data beyond what is needed to demonstrate the issue.

1. Scope

This policy covers systems controlled by CYIN, including:

  • the public CYIN website and its first-party APIs;
  • contact and CYRA registration workflows;
  • CYRA’s website integration;
  • certificate verification; and
  • authentication and access control for CYIN administrative services.

If ownership is unclear, report the issue before testing further and we will confirm scope.

2. Out of scope

  • third-party hosting, AI, identity, social-media or other provider infrastructure not controlled by CYIN;
  • denial-of-service, traffic flooding, destructive load testing or attacks on availability;
  • physical intrusion, employee impersonation, social engineering, phishing or spam;
  • automated scanning that degrades service or creates large volumes of records;
  • self-XSS, missing headers or best-practice observations without a demonstrated security impact;
  • credential stuffing using leaked credentials or testing another person’s account; and
  • publicly disclosing an unremediated issue without coordinated agreement.

3. Safe research rules

To qualify as good-faith research:

  • comply with applicable law and use only accounts and data you own or have explicit permission to test;
  • use the minimum testing needed to confirm the issue;
  • stop immediately if you access personal, confidential or sensitive information;
  • do not download, retain, alter, delete or publicly expose data;
  • do not create persistence, install malware, pivot to other systems or disrupt users;
  • give us reasonable time to investigate and remediate before any disclosure; and
  • do not demand payment, threaten disclosure or use the finding for extortion.

4. What to include in your report

  • the affected URL, endpoint or feature;
  • the vulnerability type and likely impact;
  • clear, reproducible steps and the date and time observed;
  • a minimal proof of concept, with sensitive values removed;
  • screenshots or request details that help us reproduce the issue;
  • whether any data was accessed and confirmation that it was not retained; and
  • your preferred name and contact method.

If your report contains particularly sensitive material, first ask us for a secure exchange method.

5. Our response targets

We aim to acknowledge a complete report within three business days, complete initial triage within seven business days, and provide meaningful progress updates. Remediation time depends on severity, complexity and dependencies. These are service targets, not guarantees.

We may ask for clarification, coordinate a fix and agree on a responsible disclosure date. Please keep report details confidential during that process.

6. Good-faith assurance

When research follows this policy, is lawful and is intended to improve security, CYIN will treat it as authorised good-faith activity and will not initiate legal action merely for that research. This assurance does not cover privacy violations, disruption, extortion, data misuse or actions outside this policy, and cannot bind third parties or public authorities.

7. Recognition and rewards

We appreciate responsible reports and may offer acknowledgement when appropriate and desired. This policy does not create a bug-bounty programme or promise payment. Any reward must be agreed by CYIN in writing.

8. Regulatory and incident coordination

Where a report indicates an actual incident or a legal reporting duty, CYIN may coordinate with CERT-In, affected providers, customers, regulators or law-enforcement authorities as appropriate. Do not report personal data or active incident details through public channels.

9. Security contact

Email: admin@cyinsolutions.in
Subject: SECURITY DISCLOSURE: [short title]
Alternative email: admin@cyinsolutions.com

© 2026 CYIN Solutions Pvt. Ltd.Clear rules. Responsible technology. Digital trust.cyinsolutions.in ↗