Security Posture & Safe Harbor
Our corporate security practices, responsible vulnerability disclosure guidelines, and Safe Harbor legal protections.
1. Institutional Security Posture
As practicing security architects and offensive specialists, we hold our internal infrastructure to the highest defensive standards:
- Hardware-Backed MFA: All corporate identity access and administrative console logins require hardware security keys (FIDO2 / WebAuthn). Passwords and SMS MFA are strictly prohibited for production access.
- Ephemeral & Air-Gapped Test Infrastructure: Client testing is orchestrated inside dedicated, ephemeral cloud VPCs isolated with micro-segmentation and strict outbound egress inspection.
- Cryptographic Data Lifecycle: All communications, engagement deliverables, and proof-of-concept exploit scripts are encrypted at rest using AES-256 GCM and in transit via TLS 1.3.
2. Responsible Disclosure Policy & Safe Harbor
BhishmaSec deeply respects the independent security research community. If you discover a potential vulnerability in our internet-facing infrastructure (*.bhishmasec.com), we welcome your report and pledge to cooperate under our Safe Harbor commitment.
3. Safe Harbor Legal Commitment
If you conduct security research in good faith and adhere to these guidelines, we commit that:
- We will consider your activities authorized under applicable computer crime statutes (including the Indian Information Technology Act, 2000 and Section 43/66 provisions).
- We will not initiate legal action or pursue criminal prosecution against you.
- We will collaborate transparently to validate and remediate the issue within a rapid timeline.
- We will recognize your responsible disclosure publicly on our Wall of Fame, if you wish to be credited.
4. Rules of Engagement for Researchers
To qualify under our Safe Harbor commitment, researchers must:
- Avoid accessing, viewing, modifying, or retaining any data beyond the minimum necessary to demonstrate an actionable proof of concept.
- Avoid executing Denial of Service (DoS / DDoS) attacks, automated brute-force attacks, or actions that degrade service availability for clients.
- Avoid physical security attacks, social engineering, phishing, or harassment directed against BhishmaSec personnel or contractors.
- Provide a minimum 90-day coordinated disclosure window from initial receipt before publicly discussing or publishing any vulnerability details.
5. How to Report a Vulnerability
Send your encrypted vulnerability report to: [email protected] with:
- A detailed explanation of the vulnerability and its potential security impact.
- Affected endpoint URLs, parameters, headers, or components.
- Step-by-step reproduction steps and code/payload snippets.
Our security architecture triage team will acknowledge receipt of your disclosure within twenty-four (24) hours.