Skip to main content
Security

Responsible Disclosure Policy

We take the security of our systems and our clients' data seriously. If you have found a vulnerability, we want to hear about it — and we commit to responding quickly, fixing it, and never punishing you for telling us.

Nucleus Ai Automation Private LimitedCIN U63111UW2026PTC255078Last updated — 26 July 2026

1. Our commitment

Nucleus Ai welcomes reports from security researchers, customers and members of the public. This policy sets out what you may test, how to report what you find, what protection you have when you act in good faith, and what we will do in return. It is written in line with the CERT-In Responsible Vulnerability Disclosure and Coordination Policy and the practices in ISO/IEC 29147 and ISO/IEC 30111.

2. Scope

In scope

  • this website and its subdomains;
  • web and mobile applications we publish under the Nucleus Ai name;
  • APIs and infrastructure we operate directly;
  • exposure of our data or credentials that you find in public sources.

Out of scope

  • Third-party platforms — Meta and WhatsApp, Google and RCS carriers, hosting, CDN and payment providers. Report those to the provider directly, under their own disclosure programme.
  • Client-owned systems we built or maintain but do not control. Contact the client, or write to us and we will coordinate — do not test them without the owner's authorisation.
  • Denial-of-service, volumetric or stress testing of any kind.
  • Social engineering, phishing or physical intrusion against our staff, clients or offices.
  • Spam, bulk automated scanning that degrades service, and any testing that disrupts availability for others.
  • Self-XSS, missing security headers, missing SPF/DMARC/DKIM records, cookie flags, TLS configuration grades, version disclosure and outdated-library reports, unless you can demonstrate concrete exploitability.
  • Clickjacking on pages with no sensitive state-changing action, and issues requiring physical access to an unlocked device, a rooted device or an outdated browser.
  • Vulnerabilities affecting only users of unsupported or end-of-life software.

3. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will:

  • consider your testing authorised under the Information Technology Act, 2000 and any applicable computer-misuse and anti-circumvention law;
  • not initiate or support civil or criminal action against you, and not report you to law enforcement, in relation to that research;
  • work with you to understand and resolve the issue quickly;
  • publicly acknowledge your contribution, if you would like us to.
Safe harbour is ours to give only for our own systems. It does not bind third parties, clients or platform operators, and it does not cover testing that goes beyond this policy — data exfiltration, service disruption, extortion or public disclosure before a fix. If legal action is brought against you by a third party for activity that complied with this policy, tell us and we will make that compliance known.

If you are unsure whether something is in scope or whether a test is acceptable, ask us first at hello@nucleusaiautomation.com. Asking never counts against you.

4. Rules of engagement

While researching, you must:

  • use only your own test accounts and data, and stop as soon as you have established a vulnerability exists;
  • access the minimum data necessary to demonstrate impact — never enumerate, download or retain personal data belonging to others;
  • securely delete any data you did obtain, as soon as it is reported, and confirm the deletion to us;
  • not modify, delete or corrupt data, degrade service, or install a backdoor or persistence mechanism;
  • not use automated scanners at a rate that affects availability;
  • give us reasonable time to remediate before disclosing anything publicly, and never condition a report on payment.

Threatening to disclose, sell or exploit a vulnerability unless paid is extortion, not research, and voids every protection in this policy.

5. How to report

Email hello@nucleusaiautomation.com with the subject line "Security — [short description]". Please include:

  1. the affected URL, endpoint, application or component;
  2. the vulnerability type and its impact — what an attacker could actually do;
  3. clear, reproducible steps, with a proof of concept, request/response pairs or a short video;
  4. any test account, IP address or user-agent you used, so we can distinguish your traffic from an attack;
  5. your name or handle as you would like it credited, and whether you wish to remain anonymous.

Write in English or Hindi. If the report contains sensitive data, tell us and we will arrange an encrypted channel before you send it. Please do not use the on-site chat widget or a public social media post for security reports.

6. What we will do

StageOur commitment
AcknowledgementWithin 3 business days of your report
Initial triage and severity assessmentWithin 10 business days
Status updatesAt least every 15 days until the issue is closed
Remediation — critical / highTarget 7 / 30 days from confirmation
Remediation — medium / lowTarget 60 / 90 days from confirmation
Coordinated public disclosureBy mutual agreement, ordinarily within 90 days of the fix

Where a vulnerability affects a client system or a widely deployed third-party product, we will coordinate with the client, the vendor and — where appropriate — CERT-In, and we will keep you informed of the timeline that results.

7. Recognition and rewards

We do not currently operate a paid bug bounty programme. We do offer public acknowledgement, on this page and in the release notes for the fix, for the first reporter of a previously unknown, in-scope, valid vulnerability. Where a report is exceptionally impactful and well documented, we may — entirely at our discretion — offer a token of appreciation. Duplicate reports, findings from automated scanners without demonstrated impact, and out-of-scope items are not eligible.

8. Handling of your report

We treat reports as confidential. We use the contact details you provide only to correspond about the report and to credit you if you ask, and we retain the report and its resolution as part of our security records. Our Privacy Policy applies to that data.

This page is provided for transparency and does not constitute legal advice. Where a signed agreement between us says something different, that agreement governs.

Connect. Automate. Grow.

Every day without it is a conversation your competitor is having instead. Talk to us on the channel we sell — reply time: instant.

Start the conversation →
Messaging opt-in

Get updates on your channel

Service notices, project updates and the occasional offer — on the channels you pick, and only if you ask. Reply STOP to stop any of them. Full opt-in terms →

Send me messages on *

Opens WhatsApp with your opt-in message ready to send — that is how we record it, whichever channels you picked. Free; carrier data charges apply. v2.0