Legal & Policies
Grey Shield cybersecurity firm. Effective date: 1 January 2025.
Responsible Disclosure Policy
Last updated: January 2025Grey Shield values the work of independent security researchers. If you believe you've found a security vulnerability affecting our own website or infrastructure, this page explains how to report it safely and what you can expect from us in return.
Found something? Send us the details and we'll take it from there.
Report a Vulnerability1. Scope
This policy applies only to assets owned and operated by Grey Shield — primarily greyshield.in and its subdomains. It does not apply to systems or applications belonging to our clients; those engagements are governed separately by signed authorisation and are out of scope for public reporting.
| In scope | Out of scope |
|---|---|
| greyshield.in and its subdomains | Third-party services we use but don't control (analytics, payment processors, hosting providers, email providers, etc.) |
| Web application logic, authentication, and data-handling flaws | Denial-of-service, spam, or social engineering against our staff |
| Server / infrastructure misconfigurations we control | Automated scanning that generates significant traffic without prior notice |
| Physical security, or attacks requiring physical access to our offices | |
| Reports with no realistic security impact (e.g. missing minor security headers, clickjacking on pages with no sensitive actions, self-XSS, best-practice suggestions without a working exploit) |
2. How to Report
Email contact@greyshield.in with:
- A clear description of the vulnerability and its potential impact;
- Step-by-step reproduction instructions;
- The affected URL(s), endpoint(s), or parameter(s);
- Any supporting evidence — screenshots, logs, or proof-of-concept code.
Please encrypt sensitive reports where possible; a PGP key is available on request. Report one issue per email so we can track and respond to each independently.
3. Our Commitment
| Milestone | Target |
|---|---|
| Acknowledge receipt | Within 2 business days |
| Initial triage & assessment | Within 10 business days |
| Status updates while we remediate | Roughly every 2 weeks, or on request |
| Public credit (if you'd like it) | Once a fix is deployed |
Grey Shield does not currently operate a paid bug bounty programme. Reports are handled on a goodwill and mutual-respect basis.
4. Ground Rules
To keep this process safe for everyone, please:
- Give us reasonable time to investigate and remediate before any public disclosure;
- Avoid accessing, modifying, or deleting data that isn't yours;
- Avoid actions that could degrade service availability for other users;
- Never attempt to extort, coerce, or publicly shame us in connection with a report;
- Only test against greyshield.in itself — not our clients' systems.
Safe harbour: If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue or support legal action against you for that research. This does not extend to testing performed against any system outside the scope defined above.
This safe-harbour statement reflects our own intentions and doesn't bind third parties (such as hosting or infrastructure providers) or override applicable law. If in doubt about whether an action is covered, ask us first at contact@greyshield.in.
5. Recognition
With your permission, we're happy to publicly credit researchers who report a valid, in-scope vulnerability once a fix has shipped. Let us know in your report whether you'd like to be named, and how (e.g. full name, handle, or company).