Responsible Disclosure Policy

Effective Date: 28/03/2026
Last Updated: 12/04/2026


Introduction

CIAETO Pvt. Ltd. (“CIAETO”, “Company”, “we”, “our”, or “us”) is committed to maintaining the security and integrity of our systems and services.

We value the efforts of security researchers and the community in helping identify potential vulnerabilities. This Responsible Disclosure Policy outlines how vulnerabilities can be reported and how we handle such reports.


Our Commitment

CIAETO aims to:

  • Maintain a secure environment for users and clients
  • Review and assess reported vulnerabilities in a timely manner
  • Take appropriate steps to address verified security issues

We appreciate responsible efforts that help improve our security posture.


Reporting a Vulnerability

If you believe you have identified a security vulnerability, please report it to us at:

📧 security@ciaeto.coom

Please include the following details:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected URL, system, or component
  • Supporting evidence (screenshots, logs, or proof-of-concept if available)

Providing clear and detailed information helps us investigate efficiently.


Responsible Disclosure Guidelines

We request that you:

  • Act in good faith and avoid privacy violations
  • Do not exploit the vulnerability beyond what is necessary for proof
  • Do not access, modify, or delete user data
  • Do not disrupt services or systems
  • Do not publicly disclose the issue until it has been addressed

Our Response Process

Upon receiving a valid report, CIAETO will:

  • Acknowledge receipt of the report
  • Review and validate the vulnerability
  • Take appropriate remediation actions as necessary

Response timelines may vary depending on the complexity and severity of the issue.


Legal Safe Harbor

If you act in good faith and in accordance with this policy:

CIAETO will not pursue legal action against you for responsible disclosure of vulnerabilities.

This applies only to activities that comply with this policy and applicable laws.


No Reward or Bounty

CIAETO currently does not operate a bug bounty program.

Submission of a vulnerability report does not create any expectation of financial reward or compensation.


Scope

This policy applies only to systems and services owned or controlled by CIAETO.

It does not apply to third-party platforms, services, or integrations.


Changes to This Policy

CIAETO may update this Responsible Disclosure Policy from time to time.

Updates will be reflected with a revised “Last Updated” date.


Contact Us

For vulnerability reporting or related inquiries:

CIAETO Pvt. Ltd.
🌐 [usite]
📧 security@ciaeto.coom