Security & Responsible Disclosure Policy
Guidelines and safe-harbor principles for reporting potential security vulnerabilities in CredSecure responsibly.
1. Reporting Security Vulnerabilities
If you believe you have discovered a potential security vulnerability in the CredSecure public website (getcredsecure.com), please report it to us privately:
Security Contact Email: customer-support@getcredsecure.com
Subject Line: Security Vulnerability Report — CredSecure
Please do not send live credentials, production tokens, private keys, or unnecessary personal information in your initial report.
2. Good-Faith Research Rules
Researchers participating in vulnerability discovery must:
- Test only systems you are authorized to test;
- Minimise impact and avoid data destruction or service disruption;
- Stop testing immediately if customer credentials or sensitive data are unexpectedly exposed;
- Do not disrupt services, introduce persistence, extort, phish or pivot to unrelated systems; and
- Allow reasonable time for investigation before any public disclosure.
CredSecure is deployed in customer-controlled infrastructure. This policy does not grant permission to test any customer CredSecure deployment, network, database, or integrated system.
Testing a customer environment requires explicit, separate written authorization from that specific customer organization. Unauthorized testing of customer infrastructure constitutes illegal activity.
4. Encouraged Issues
We encourage responsible reports regarding:
- Authentication or authorization bypass;
- Privilege escalation;
- Unauthorized credential or secret exposure in public endpoints;
- Material API authorization weaknesses;
- Reproducible security vulnerabilities materially affecting confidentiality, integrity or availability.
5. Safe Harbor Intent
Innodhee supports good-faith security research conducted lawfully and in accordance with this policy. Where a researcher makes a genuine effort to comply with this policy, avoids harm, promptly reports the issue, and does not misuse information obtained during testing, Innodhee intends to treat the activity as responsible security research rather than malicious activity.
6. Contact
Contact Email: customer-support@getcredsecure.com
Innodhee Services Pvt. Ltd., Bengaluru, Karnataka, India
Legal Entity Details
RI Elegance, Parappana Agrahara Main Rd,
Sai Sree Layout, Parappana Agrahara,
Bengaluru, Karnataka 560100, India
Deployment Model Notice
Under the standard CredSecure deployment model, the application, database and customer credential data are deployed within the customer's designated infrastructure or landscape and are not centrally hosted by Innodhee.