Maharaja Agrasen Foundation Limited Singapore believes in coordinating with security researchers to secure our directory platform. If you discover a security vulnerability in our codebase or infrastructure, we ask you to report it to us responsibly.
1. Reporting Vulnerabilities
Please email vulnerability findings to:
security@agrasenfoundation.org
Please include a detailed description of the issue, steps to reproduce, and any relevant screenshot or proof-of-concept script. Please do not disclose the vulnerability publicly until we have patched it.
2. Guidelines for Researchers
To ensure a safe disclosure process, we ask that you adhere to the following rules:
- Do not access, download, or modify data belonging to other community members.
- Do not execute denial of service (DoS/DDoS) attacks or run high-frequency automated vulnerability scanners that impact system performance.
- Do not use social engineering, phishing, or physical security attacks against our staff, moderators, or community members.
3. Our Commitment
If you follow these guidelines, we commit to:
- Acknowledging receipt of your report within 48 hours.
- Providing a timeline for patching the reported vulnerability.
- Not initiating legal action against you for research conducted in compliance with this policy.
