Back to HomeSecurity & Disclosure

Security & Responsible Disclosure Policy

Guidelines and safe-harbor principles for reporting potential security vulnerabilities in CredSecure responsibly.

Last Updated: September 2026Official Domain: getcredsecure.com

1. Reporting Security Vulnerabilities

If you believe you have discovered a potential security vulnerability in the CredSecure public website (getcredsecure.com), please report it to us privately:

Security Contact Email: customer-support@getcredsecure.com

Subject Line: Security Vulnerability Report — CredSecure

Please do not send live credentials, production tokens, private keys, or unnecessary personal information in your initial report.

2. Good-Faith Research Rules

Researchers participating in vulnerability discovery must:

  • Test only systems you are authorized to test;
  • Minimise impact and avoid data destruction or service disruption;
  • Stop testing immediately if customer credentials or sensitive data are unexpectedly exposed;
  • Do not disrupt services, introduce persistence, extort, phish or pivot to unrelated systems; and
  • Allow reasonable time for investigation before any public disclosure.
3. Customer Environments Are Not Public Test Targets

CredSecure is deployed in customer-controlled infrastructure. This policy does not grant permission to test any customer CredSecure deployment, network, database, or integrated system.

Testing a customer environment requires explicit, separate written authorization from that specific customer organization. Unauthorized testing of customer infrastructure constitutes illegal activity.

4. Encouraged Issues

We encourage responsible reports regarding:

  • Authentication or authorization bypass;
  • Privilege escalation;
  • Unauthorized credential or secret exposure in public endpoints;
  • Material API authorization weaknesses;
  • Reproducible security vulnerabilities materially affecting confidentiality, integrity or availability.

5. Safe Harbor Intent

Innodhee supports good-faith security research conducted lawfully and in accordance with this policy. Where a researcher makes a genuine effort to comply with this policy, avoids harm, promptly reports the issue, and does not misuse information obtained during testing, Innodhee intends to treat the activity as responsible security research rather than malicious activity.

6. Contact

Contact Email: customer-support@getcredsecure.com
Innodhee Services Pvt. Ltd., Bengaluru, Karnataka, India

Legal Entity Details

Innodhee Services Pvt. Ltd.

RI Elegance, Parappana Agrahara Main Rd,
Sai Sree Layout, Parappana Agrahara,
Bengaluru, Karnataka 560100, India

Deployment Model Notice

Under the standard CredSecure deployment model, the application, database and customer credential data are deployed within the customer's designated infrastructure or landscape and are not centrally hosted by Innodhee.