Responsible Disclosure
Report a Vulnerability
We work with the security community to keep Vistaan and our customers safe. If you have found a vulnerability, please report it to us privately so we can investigate and fix the issue before public disclosure.
Policy
Scope
- Production web properties under vistaan.com and its subdomains
- Authenticated and unauthenticated access paths to customer-facing services
- Configuration and hardening of infrastructure under Vistaan control
Out of scope
- Denial-of-service attacks and rate-limit exhaustion
- Social engineering of Vistaan staff or contractors
- Vulnerabilities in third-party platforms we do not own
- Self-XSS or issues requiring unlikely user interaction
Our commitments
- Acknowledge your report within 2 business days
- Provide a triage update within 5 business days
- Share a remediation timeline once a fix is scoped
- Credit researchers who follow the policy and request acknowledgement
Safe harbor
- We will not pursue legal action for good-faith research that follows this policy
- Research conducted under this policy is authorized and considered authorized access
- You are not required to retain exfiltrated data — please delete it after confirmation
Secure contact channels
PGP fingerprint
3F4A 8C9B 21D6 7E05 9A11 6B22 4D88 7E33 0C55 91AB
Use this key when sending sensitive vulnerability details.
Signal
@vistaan-sec
Request a secure channel via Signal for high-severity reports.
Send a private report
Prefer to use the form? Submissions from this page go to our security team.