Responsible disclosure

Security Policy

Found a vulnerability in something we run? Thank you for telling us first. Here's how to report it — and what you can expect from us in return.

Last updated: July 15, 2026

Report privately

Email contact@sivro.in with "Security" in the subject line.

Fast acknowledgment

We confirm receipt within 3 business days and keep you updated.

Safe harbor

Good-faith research under this policy will not lead to legal action.

01

Our commitment

SIVRO takes the security of our website, client projects, and users seriously. We appreciate the work of security researchers and believe responsible disclosure makes the web safer for everyone.

If you believe you have found a security vulnerability in anything we operate, we want to hear from you — and we will work with you to understand, validate, and fix the issue quickly.

02

How to report a vulnerability

Send a report to contact@sivro.in with "Security" in the subject line. Please include: a description of the issue and where it was found, step-by-step instructions to reproduce it, the potential impact as you understand it, and any proof-of-concept code or screenshots that help us verify it.

Please report in English, and give us a reasonable amount of time to investigate and fix the issue before disclosing it publicly.

03

What to expect from us

We will acknowledge your report within 3 business days, keep you informed as we investigate, and let you know when the issue is resolved. If your report leads to a fix, we are happy to credit you publicly — or keep you anonymous if you prefer.

04

Scope

This policy covers the sivro.in website and the services we directly operate. Client websites and third-party platforms we integrate with (hosting providers, analytics, payment processors) are out of scope — please report issues with those to the respective vendor.

05

Out of scope

The following are not considered qualifying vulnerabilities: denial-of-service or volumetric attacks, spam or social-engineering of SIVRO staff or clients, physical attacks, reports from automated scanners without a demonstrated impact, clickjacking on pages with no sensitive actions, and missing security headers or best-practice flags without a practical exploit.

Please never access, modify, or delete data that is not your own, and do not degrade the service for other users while testing.

06

Safe harbor

We will not pursue legal action against researchers who: act in good faith and within this policy, avoid privacy violations and destruction of data, do not exploit an issue beyond what is needed to demonstrate it, and give us reasonable time to remediate before any public disclosure.

Machine-readable version

This policy is also published per RFC 9116 at /.well-known/security.txt. Report vulnerabilities to contact@sivro.in.