Vulnerability Disclosure Program

Overview

Welcome to our Vulnerability Disclosure Program (VDP) At Data Security Council of India (DSCI), we take the security of our web application very seriously and believe that the best way to ensure that our platform is secure is through the help of the security community. We invite all security researchers to participate in our Vulnerability Disclosure Program, and we are committed to working with the community to acknowledge and fix any vulnerabilities that are discovered.

How to participate

1

Review our program scope

Our program scope includes only our web application. Please do not attempt to exploit any other system or application owned by our company.

2

Find a security vulnerability

Once you have reviewed our program scope, start looking for security vulnerabilities in our web application. Please ensure you follow responsible disclosure practices and do not disclose any vulnerabilities publicly until we have had the opportunity to address them.

3

Report the vulnerability

Report the vulnerability to us using the submit form at the bottom of the page. Please include a detailed description of the vulnerability, along with any supporting evidence such as screenshots or videos.

Program Rules

To participate in our Vulnerability Disclosure Program , you must agree to the following rules
Do not attempt to exploit any other system or application owned by our company.
Do not publicly disclose any vulnerabilities until we have had the opportunity to address them.
Do not perform any denial of service attacks or spamming activities.
Do not compromise the privacy of our users.
Do not attempt to gain access to our users’ personal information.
Do not attempt to access any financial or payment information.
Do not attempt to modify or delete any data.
Do not attempt to perform any social engineering attacks.
Only test against our scoped use cases.
Only test vulnerabilities that are within the program scope.
Do not share any details of the vulnerability with any third party without our consent.
Any attempt to exploit a vulnerability outside of the program scope is strictly prohibited.

Scope

The Vulnerability Disclosure Program will cover only designated systems and services. These include our websites, web applications, mobile applications, and other software products.

Use case: www.dsci.in

Type: Web-Application

Visit site

Use case: www.techsagar.in

Type: Web-Application

Visit site

Use case: www.n-coe.in

Type: Web-Application

Visit site

Use case: ccoe.dsci.in

Type: Web-Application

Visit site

Program Features
Eligibility

The Vulnerability Disclosure Program is open to all individuals, except for employees and contractors of the company.

Confidentiality

We will treat all bug reports as confidential, and we will not share any information about the report or the researcher without their permission, except as required by law.

No legal action

We will not take any legal action against researchers who make a good-faith effort to report security vulnerabilities to us.

Non-compliance

We reserve the right to exclude individuals from participating in the vulnerability disclosure program if they violate any of the rules or engage in any unethical behavior.

Disclaimer

We reserve the right to modify or cancel the vulnerability disclosure program at any time, without notice. We are not responsible for any damages or losses that may arise from participation in the vulnerability disclosure program.

 

Reporting

Please provide the following information in your report
Only test against our scoped use cases.
Only test vulnerabilities that are within the program scope.
Do not share any details of the vulnerability with any third party without our consent.
Any attempt to exploit a vulnerability outside of the program scope is strictly prohibited.

We will review your submission, If required we will connect with you. Please note that we may need additional information or clarification from you, and we appreciate your cooperation in this process. We encourage all participants to adhere to our responsible disclosure policy and not disclose any vulnerabilities publicly until we have had the opportunity to investigate and fix them. We also reserve the right to modify the terms of this program at any time. For any query write to us at vulnerability[at]dsci[dot]in