Grey Shield GreyShield
Company
About Us Methodology Industries
Contact Us Career Responsible Disclosure
Services
Application Security Web Application Testing OWASP-based testing for web apps & APIs Mobile App Security Testing iOS & Android app assessments Source Code Review Manual & automated secure code audits
Infrastructure Security Network Penetration Testing Internal & external infrastructure testing Cloud Security Assessment AWS, Azure & GCP configuration reviews OT / ICS Security Testing Industrial control & SCADA environments
Development Services Web Development Responsive websites & web platforms Mobile App Development Native iOS & Android applications Software Development Custom software & backend systems UI/UX Design Interfaces designed around real users
Advanced Testing Red Team Operations Real-world adversary simulation

Not sure which service fits your organization?

View All Services
Research
Resources
Blog Case Studies Whitepapers & Reports
View All Resources
vulnfield
Get Assessment
Company
About Us Methodology Industries Contact Us Career Responsible Disclosure
Services
Application Security Web Application Security Testing Mobile App Security Testing Source Code Review Infrastructure Security Network Penetration Testing Cloud Security Assessment OT / ICS Security Testing Development Services Web Development Mobile App Development Software Development UI/UX Design Advanced Testing Red Team Operations
View All Services
Research
Resources
Blog Case Studies Whitepapers & Reports View All Resources
vulnfield Get Assessment
// LEGAL

Legal & Policies

Grey Shield cybersecurity firm. Effective date: 1 January 2025.

Privacy Policy Terms of Service Responsible Disclosure
On this page
  • 1. Scope
  • 2. How to Report
  • 3. Our Commitment
  • 4. Ground Rules
  • 5. Recognition
  • 6. Contact

Responsible Disclosure Policy

Last updated: January 2025

Grey Shield values the work of independent security researchers. If you believe you've found a security vulnerability affecting our own website or infrastructure, this page explains how to report it safely and what you can expect from us in return.

Found something? Send us the details and we'll take it from there.

Report a Vulnerability

1. Scope

This policy applies only to assets owned and operated by Grey Shield — primarily greyshield.in and its subdomains. It does not apply to systems or applications belonging to our clients; those engagements are governed separately by signed authorisation and are out of scope for public reporting.

In scopeOut of scope
greyshield.in and its subdomains Third-party services we use but don't control (analytics, payment processors, hosting providers, email providers, etc.)
Web application logic, authentication, and data-handling flaws Denial-of-service, spam, or social engineering against our staff
Server / infrastructure misconfigurations we control Automated scanning that generates significant traffic without prior notice
  Physical security, or attacks requiring physical access to our offices
  Reports with no realistic security impact (e.g. missing minor security headers, clickjacking on pages with no sensitive actions, self-XSS, best-practice suggestions without a working exploit)

2. How to Report

Email contact@greyshield.in with:

  • A clear description of the vulnerability and its potential impact;
  • Step-by-step reproduction instructions;
  • The affected URL(s), endpoint(s), or parameter(s);
  • Any supporting evidence — screenshots, logs, or proof-of-concept code.

Please encrypt sensitive reports where possible; a PGP key is available on request. Report one issue per email so we can track and respond to each independently.


3. Our Commitment

MilestoneTarget
Acknowledge receiptWithin 2 business days
Initial triage & assessmentWithin 10 business days
Status updates while we remediateRoughly every 2 weeks, or on request
Public credit (if you'd like it)Once a fix is deployed

Grey Shield does not currently operate a paid bug bounty programme. Reports are handled on a goodwill and mutual-respect basis.


4. Ground Rules

To keep this process safe for everyone, please:

  • Give us reasonable time to investigate and remediate before any public disclosure;
  • Avoid accessing, modifying, or deleting data that isn't yours;
  • Avoid actions that could degrade service availability for other users;
  • Never attempt to extort, coerce, or publicly shame us in connection with a report;
  • Only test against greyshield.in itself — not our clients' systems.

Safe harbour: If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue or support legal action against you for that research. This does not extend to testing performed against any system outside the scope defined above.

This safe-harbour statement reflects our own intentions and doesn't bind third parties (such as hosting or infrastructure providers) or override applicable law. If in doubt about whether an action is covered, ask us first at contact@greyshield.in.


5. Recognition

With your permission, we're happy to publicly credit researchers who report a valid, in-scope vulnerability once a fix has shipped. Let us know in your report whether you'd like to be named, and how (e.g. full name, handle, or company).


6. Contact

Security reports & legal enquiries

contact@greyshield.in

On this page
  • Scope
  • How to Report
  • Our Commitment
  • Ground Rules
  • Recognition
  • Contact
Grey Shield GreyShield

Enterprise-grade penetration testing and cybersecurity services that help organisations identify and eliminate real-world threats before attackers do.

Services

  • Web App Pen Testing
  • Network Pen Testing
  • Cloud Security
  • Red Team Operations

Company

  • About Us
  • Contact Us
  • All Services

Legal

  • Privacy Policy
  • Terms of Service
  • Responsible Disclosure
© 2026 Grey Shield. All rights reserved. Udyam Reg. No: UDYAM-HR-07-0029134
All systems operational