Legal
Responsible Disclosure
If you have found a security issue in a Deep Heuristics system, we want to hear about it, and we will not pursue you for telling us.
Pending legal review. This notice is drafted to reflect how Deep Heuristics intends to operate, but it has not been settled by qualified counsel in the relevant jurisdictions. It must be reviewed and approved before the site is published to a live audience.
How to report
Send your report to [email protected] with “Security disclosure” in the subject line. Please include:
- The affected system, URL, or endpoint.
- A description of the issue and its likely impact.
- Steps to reproduce, with any request or response detail needed.
- Whether you have disclosed the issue to anyone else.
- How you would like to be credited, if at all.
If a report requires encryption, request our current PGP key in your first message and we will supply it before you send technical detail. Placeholder: publish a key fingerprint here, or remove this paragraph, before launch.
What we commit to
- Acknowledgement within 3 business days of receiving your report.
- An initial assessment within 10 business days, telling you whether we have reproduced the issue and how we have rated it.
- Progress updates at least every 15 business days until the issue is resolved or closed.
- Credit on resolution, if you want it and the report is valid.
- No legal action against you for good-faith research conducted within the terms below.
Safe harbour
We will treat research as authorised, and will not initiate or support legal action against you, where you act in good faith and:
- Test only systems Deep Heuristics owns and operates — not client systems, and not third-party services we merely use.
- Stop as soon as you have established that a vulnerability exists, and do not pivot further into our environment.
- Access only the minimum data needed to demonstrate the issue, and do not download, retain, alter, or disclose data belonging to us or to anyone else.
- Do not degrade availability — no denial of service, resource exhaustion, or high-volume automated scanning.
- Do not use social engineering, physical intrusion, or attacks against our staff or suppliers.
- Give us a reasonable period to remediate before any public disclosure.
If you are unsure whether an activity falls within these terms, ask us first. We would rather answer a question than receive a report we cannot protect you over.
Out of scope
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags, or TLS configuration preferences with no demonstrated exploit.
- Rate limiting and volumetric issues, and self-inflicted or social-engineering-dependent scenarios.
- Vulnerabilities in third-party services we do not control — report those to their owners.
- Reports concerning client systems assessed by us. Those go to the system owner, not to us.
Our own disclosure practice
The same discipline applies to research we conduct. Where our security research identifies a weakness in an identifiable third-party product, we notify the vendor first and agree a remediation window before publication. We publish at the end of that window whether or not a fix has shipped, and we do not release working exploit code against systems that are live and unpatched.
Contact
[email protected]
Deep Heuristics, 6b Garden Road, Chennai, Tamil Nadu 603112, India