Responsible Disclosure Policy
We take the security of our systems and our clients' data seriously. If you have found a vulnerability, we want to hear about it — and we commit to responding quickly, fixing it, and never punishing you for telling us.
1. Our commitment
Nucleus Ai welcomes reports from security researchers, customers and members of the public. This policy sets out what you may test, how to report what you find, what protection you have when you act in good faith, and what we will do in return. It is written in line with the CERT-In Responsible Vulnerability Disclosure and Coordination Policy and the practices in ISO/IEC 29147 and ISO/IEC 30111.
2. Scope
In scope
- this website and its subdomains;
- web and mobile applications we publish under the Nucleus Ai name;
- APIs and infrastructure we operate directly;
- exposure of our data or credentials that you find in public sources.
Out of scope
- Third-party platforms — Meta and WhatsApp, Google and RCS carriers, hosting, CDN and payment providers. Report those to the provider directly, under their own disclosure programme.
- Client-owned systems we built or maintain but do not control. Contact the client, or write to us and we will coordinate — do not test them without the owner's authorisation.
- Denial-of-service, volumetric or stress testing of any kind.
- Social engineering, phishing or physical intrusion against our staff, clients or offices.
- Spam, bulk automated scanning that degrades service, and any testing that disrupts availability for others.
- Self-XSS, missing security headers, missing SPF/DMARC/DKIM records, cookie flags, TLS configuration grades, version disclosure and outdated-library reports, unless you can demonstrate concrete exploitability.
- Clickjacking on pages with no sensitive state-changing action, and issues requiring physical access to an unlocked device, a rooted device or an outdated browser.
- Vulnerabilities affecting only users of unsupported or end-of-life software.
3. Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will:
- consider your testing authorised under the Information Technology Act, 2000 and any applicable computer-misuse and anti-circumvention law;
- not initiate or support civil or criminal action against you, and not report you to law enforcement, in relation to that research;
- work with you to understand and resolve the issue quickly;
- publicly acknowledge your contribution, if you would like us to.
If you are unsure whether something is in scope or whether a test is acceptable, ask us first at hello@nucleusaiautomation.com. Asking never counts against you.
4. Rules of engagement
While researching, you must:
- use only your own test accounts and data, and stop as soon as you have established a vulnerability exists;
- access the minimum data necessary to demonstrate impact — never enumerate, download or retain personal data belonging to others;
- securely delete any data you did obtain, as soon as it is reported, and confirm the deletion to us;
- not modify, delete or corrupt data, degrade service, or install a backdoor or persistence mechanism;
- not use automated scanners at a rate that affects availability;
- give us reasonable time to remediate before disclosing anything publicly, and never condition a report on payment.
Threatening to disclose, sell or exploit a vulnerability unless paid is extortion, not research, and voids every protection in this policy.
5. How to report
Email hello@nucleusaiautomation.com with the subject line "Security — [short description]". Please include:
- the affected URL, endpoint, application or component;
- the vulnerability type and its impact — what an attacker could actually do;
- clear, reproducible steps, with a proof of concept, request/response pairs or a short video;
- any test account, IP address or user-agent you used, so we can distinguish your traffic from an attack;
- your name or handle as you would like it credited, and whether you wish to remain anonymous.
Write in English or Hindi. If the report contains sensitive data, tell us and we will arrange an encrypted channel before you send it. Please do not use the on-site chat widget or a public social media post for security reports.
6. What we will do
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 3 business days of your report |
| Initial triage and severity assessment | Within 10 business days |
| Status updates | At least every 15 days until the issue is closed |
| Remediation — critical / high | Target 7 / 30 days from confirmation |
| Remediation — medium / low | Target 60 / 90 days from confirmation |
| Coordinated public disclosure | By mutual agreement, ordinarily within 90 days of the fix |
Where a vulnerability affects a client system or a widely deployed third-party product, we will coordinate with the client, the vendor and — where appropriate — CERT-In, and we will keep you informed of the timeline that results.
7. Recognition and rewards
We do not currently operate a paid bug bounty programme. We do offer public acknowledgement, on this page and in the release notes for the fix, for the first reporter of a previously unknown, in-scope, valid vulnerability. Where a report is exceptionally impactful and well documented, we may — entirely at our discretion — offer a token of appreciation. Duplicate reports, findings from automated scanners without demonstrated impact, and out-of-scope items are not eligible.
8. Handling of your report
We treat reports as confidential. We use the contact details you provide only to correspond about the report and to credit you if you ask, and we retain the report and its resolution as part of our security records. Our Privacy Policy applies to that data.
This page is provided for transparency and does not constitute legal advice. Where a signed agreement between us says something different, that agreement governs.
Connect. Automate. Grow.
Every day without it is a conversation your competitor is having instead. Talk to us on the channel we sell — reply time: instant.
Start the conversation →Get updates on your channel
Service notices, project updates and the occasional offer — on the channels you pick, and only if you ask. Reply STOP to stop any of them. Full opt-in terms →