# Garuda Yantra Technologies — security contact # https://garudayantra.com # # If you believe you have found a security vulnerability in any Garuda Yantra # service, please tell us before you tell anyone else. We read every report and # we reply to every report. Contact: mailto:security@garudayantra.com Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en, ta, hi Canonical: https://garudayantra.com/.well-known/security.txt # ─── In scope ──────────────────────────────────────────────────────────────── # garudayantra.com and its subdomains, including: # my.garudayantra.com (client portal) # panel.garudayantra.com (control panel) # demos.garudayantra.com (demo launcher) # demo-*.garudayantra.com (industry demo tenants) # The Garuda HCM mobile app (Android / iOS). # # ─── Out of scope ──────────────────────────────────────────────────────────── # Denial of service, volumetric or load testing of any kind. # Social engineering of our staff, customers, or vendors. # Physical attacks against our offices or infrastructure providers. # Reports generated solely by an automated scanner, with no demonstrated impact. # Missing security headers or weak TLS ciphers with no demonstrated exploit. # Anything that would access, modify, or exfiltrate another customer's data — # stop at proof of access and report it. Do not pivot. # # ─── What we ask ───────────────────────────────────────────────────────────── # Use the demo tenants for testing wherever possible. They reset daily. # Give us 90 days before public disclosure. If it takes us longer, we will # tell you why. # # ─── What we commit to ─────────────────────────────────────────────────────── # Acknowledgement within 72 hours. # A triage decision (accepted / duplicate / out of scope) within 7 days. # Credit in our release notes if you want it, anonymity if you prefer. # We will not pursue legal action against researchers who report in good # faith, act within this scope, and do not access or destroy customer data. # # We are a small team and we do not currently run a paid bug bounty.