Responsible Disclosure Policy
Effective Date: 15th July 2026
AgileApt Solutions Private Limited takes the security of our website and Product seriously. We value the work of security researchers and the wider community in helping us identify and address vulnerabilities. This Responsible Disclosure Policy explains how to report a security vulnerability to us and what you can expect in return.
See also our product-level Security & Compliance page - this legal policy governs the reporting process itself.
1. Scope
This policy applies to:
- Our website: https://procurengine.ai
- Our procurement SaaS Product and its associated production infrastructure, to the extent publicly accessible
It does not apply to third-party services we use (e.g., Cloudflare, Zoho, Google, LinkedIn) - please report vulnerabilities in those platforms directly to the respective vendor.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability, please report it to us at:
Email: [email protected]
Please include, where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including affected URL(s), request/response samples, or proof-of-concept code
- Any tools used
- Your contact details, for follow-up questions
3. Our Commitment to You
When you report a vulnerability in good faith and in accordance with this policy, we commit to:
- Acknowledge receipt of your report within 3 business days
- Provide an initial assessment/triage within 10 business days
- Keep you reasonably informed of our progress towards resolution
- Not pursue or support legal action against you for good-faith research conducted in accordance with this policy
- Credit your discovery (with your permission) once the issue is resolved, where you wish to be acknowledged
We do not currently offer a paid bug bounty program. Recognition and/or a token of appreciation may be extended at our sole discretion.
4. Ground Rules (Safe Harbor)
To help us protect our users while your research is ongoing, please:
- Give us reasonable time to investigate and remediate an issue before disclosing it publicly
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services
- Only interact with accounts you own or with explicit permission from the account holder
- Do not access, download, modify, or delete data that does not belong to you
Activities conducted in good-faith compliance with this policy will be considered authorised, and we will not initiate or support legal action against individuals for such activity.
5. Out of Scope
The following are generally considered out of scope unless you can demonstrate a concrete, exploitable security impact:
- Denial-of-service (DoS/DDoS) attacks or any testing that degrades service availability
- Social engineering, phishing, or physical attacks against our employees, users, or offices
- Spam or content-injection attacks with no security impact
- Automated vulnerability scanning that generates excessive traffic without prior coordination
- Reports based solely on outdated browser/software versions, missing security headers, or best-practice recommendations without a demonstrated exploit
- Vulnerabilities in third-party services not operated by us
6. Confidentiality
Please keep any vulnerability details confidential until we have had a reasonable opportunity to investigate and remediate, and we have mutually agreed on public disclosure (if any).
7. Contact Us
AgileApt Solutions Private Limited
B-821, Advant Navis Business Park, Noida - 201305, Uttar Pradesh, India
Email: [email protected]