Responsible Disclosure Policy
We welcome responsible security research on networkz.in. If you have found a vulnerability, please report it privately before public disclosure. We will acknowledge, investigate, and respond promptly.
Thank You
We genuinely appreciate security researchers who take the time to investigate and responsibly disclose vulnerabilities. Your effort helps us protect our visitors and clients. We will acknowledge every valid report and work with you in good faith.
1. Introduction
NETWORKZ ("Networkz") takes the security of networkz.in and our client systems seriously. We believe that responsible security research makes the internet safer for everyone. This policy sets out how to report a vulnerability to us, what you can expect in return, and the boundaries within which research may be conducted.
We ask that you comply with this policy and coordinate disclosure with us before making any vulnerability publicly known. We commit to working with you in good faith and will not take legal action against researchers who act within the bounds of this policy.
2. Scope — In Scope Systems
The following systems are in scope for responsible security research:
- networkz.in — the main website and contact form
- api.networkz.in — any public API endpoints
- Any other subdomain explicitly listed in a future update to this policy
Types of vulnerabilities we are particularly interested in receiving reports about:
- Cross-site scripting (XSS)
- SQL injection or database access vulnerabilities
- Authentication bypass or broken access control
- Sensitive data exposure
- Security misconfiguration
- Server-side request forgery (SSRF)
- Remote code execution
- Insecure direct object references
- Significant information disclosure
3. Out of Scope
The following are out of scope for this policy:
- Third-party services and infrastructure (Vercel, Cloudflare, Upstash, Resend) — please report those vulnerabilities directly to the respective vendors
- Social engineering attacks targeting Networkz staff
- Physical attacks on infrastructure
- Denial of service (DoS/DDoS) attacks
- Clickjacking on pages with no sensitive actions
- Missing HTTP headers that do not result in a practical vulnerability
- Issues that require physical access to the device
- Vulnerabilities in software we do not maintain or control
- Reports generated entirely by automated scanners without manual verification
4. How to Report a Vulnerability
To report a security vulnerability, please send an email to:
Please do not disclose the vulnerability publicly (on social media, forums, or in blog posts) until we have had an opportunity to investigate and release a fix.
5. What to Include in Your Report
A useful vulnerability report includes:
- A clear description of the vulnerability and its potential impact;
- The URL or endpoint affected;
- Step-by-step reproduction instructions;
- Screenshots, HTTP request/response logs, or a proof-of-concept (PoC) — please limit PoCs to confirming the vulnerability only and do not exfiltrate real data;
- The tools or methods used;
- Your assessment of the severity (low, medium, high, critical) and the basis for that assessment.
The more detail you provide, the faster we can reproduce, assess, and fix the issue.
6. Response Times
| Stage | Target Response Time |
|---|---|
| Initial acknowledgement of your report | Within 48 hours of receipt |
| Triage and severity assessment | Within 7 days |
| Status update (remediation plan) | Within 14 days of triage |
| Remediation and notification | Depends on complexity; communicated after triage |
We will keep you informed as we work through the issue. We may ask for additional details or clarifications, and we ask for your patience in complex cases.
7. Safe Harbour Statement
We will not initiate civil or criminal legal action against security researchers who:
- discover and report vulnerabilities in good faith, in accordance with this policy;
- avoid accessing or modifying data beyond what is necessary to confirm the vulnerability;
- do not exfiltrate, alter, destroy, or publicly disclose data discovered during research;
- do not cause or attempt to cause degradation of service to our website or infrastructure;
- provide us with a reasonable period to investigate and remediate before any public disclosure.
This safe harbour applies to research conducted in good faith within the scope and conduct rules of this policy. It does not apply to activity that falls outside the scope or violates the conduct rules in Sections 8 and 9.
We cannot speak for the legal position of third parties. If you discover a vulnerability that also affects a third-party service we use, we recommend coordinating disclosure with that party separately.
8. Researcher Conduct — What You May Do
Within the bounds of this policy, you may:
- Test in-scope systems to identify security vulnerabilities;
- Use testing tools commonly used by security researchers (e.g., Burp Suite, OWASP ZAP) in a controlled and targeted manner;
- Create test accounts or test submissions to confirm a vulnerability, provided you immediately delete or request deletion of any data created;
- Report the vulnerability to us via the process in Section 4.
9. Prohibited Actions
The following actions are strictly prohibited and will void the safe harbour:
- Accessing, downloading, modifying, or deleting data that is not your own;
- Conducting denial-of-service or distributed denial-of-service (DDoS) attacks;
- Executing or attempting to execute arbitrary code on our systems;
- Pivoting from our systems to attack third-party infrastructure;
- Sending phishing emails or engaging in social engineering;
- Testing out-of-scope systems;
- Disclosing vulnerability details publicly before we have issued a fix (or agreed a coordinated disclosure date with you);
- Sharing vulnerability details with third parties without our prior written consent.
10. Bug Bounty Programme
Networkz does not currently operate a paid bug bounty programme. We cannot offer financial rewards for vulnerability reports at this time.
We do offer our sincere thanks and, for significant findings, will acknowledge researchers in a Hall of Fame section if and when we launch one, with your consent.
11. Contact
All security disclosures should be directed to hello@networkz.inwith the subject line "Security Disclosure — [Brief Description]".
For general security information about our website, see our Security Statement.