Responsible Disclosure Policy

Updated Jul 11, 2026 · Effective Jul 11, 2026

1. The invitation

Security research done in good faith makes every seeker safer, and Yagyanam welcomes it. If you discover a vulnerability in the website, the seeker app, the Expert app or our infrastructure, report it to hello@yagyanam.com with the subject "Security", and include steps to reproduce, the scope you touched, and a way to reach you.

2. The rules of engagement

  • Do not access, alter or exfiltrate another person's data; use test accounts you control.
  • No denial-of-service, no social engineering of the Care Team or experts, no physical intrusion.
  • Give us a reasonable window to fix before any public disclosure — we ask 90 days, and we move much faster than that in practice.
  • Stay within the law; this policy is our authorisation for good-faith research within these rules, and we will not initiate action against research that honours them.

3. What we do

StageTime
AcknowledgementWithin 48 hours
Triage and severityWithin 5 business days
Fix or mitigation for confirmed issuesPrioritised by severity; critical issues immediately
CreditWith your consent, researchers are thanked by name once the fix ships

Personal data possibly touched by a vulnerability is handled under the Privacy Policy's breach provisions, including notification to the Data Protection Board of India and affected users where the DPDP Rules require it.

Other documents

All terms and policies