Legal
Responsible Disclosure Policy
1. Our commitment
As a security consultancy, Pinnacle Shield takes the security of its own systems seriously and welcomes reports from independent security researchers who discover vulnerabilities in good faith. This policy describes how to report a vulnerability to us and what you can expect in return.
2. Scope
This policy covers this website and any systems we directly operate in connection with it (for example, our website hosting and form-intake infrastructure). It does not cover third-party services we merely link to or embed, or Microsoft products and services themselves — vulnerabilities in Microsoft's own platforms should be reported directly to Microsoft's Security Response Center.
3. How to report a vulnerability
Email hello@pinnashield.com with sufficient detail for us to understand and reproduce the issue. Where possible, please encrypt sensitive details, and avoid including any personal data belonging to third parties in your report.
4. What to include in your report
- A clear description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept code or screenshots
- The URL, endpoint, or system affected
- Your contact details, if you would like an acknowledgement or update
5. Our commitment to you
We will acknowledge receipt of your report within 5 business days, provide an initial assessment within 15 business days, and keep you reasonably informed of remediation progress. We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy, and who do not violate the ground rules below.
6. Ground rules
To qualify for safe-harbour treatment under this policy, you must:
- Avoid privacy violations, data destruction, and interruption or degradation of our services
- Only interact with accounts and data you own, or with explicit permission from the account holder
- Not exploit a vulnerability beyond the minimum extent necessary to confirm it exists (no bulk data extraction)
- Not perform denial-of-service testing, social engineering, or phishing against our staff
- Not publicly disclose the vulnerability until we have had reasonable time to remediate it (coordinated disclosure)
- Comply with applicable law, including the Information Technology Act, 2000
7. Legal safe harbour
We consider security research conducted consistently with this policy to be authorized in relation to the systems in scope, and we will not initiate or support legal action against you for that research, including under the Information Technology Act, 2000, where your conduct remains within the ground rules above. This safe harbour does not extend to third-party systems, and we cannot bind the decisions of third parties or government authorities.
Where applicable, we comply with directions issued by the Indian Computer Emergency Response Team ('CERT-In') regarding cybersecurity incident reporting.
8. Recognition
We do not currently operate a paid bug bounty program. With your permission, we are happy to publicly credit researchers who make a valid report under this policy.
9. Contact us
Report vulnerabilities to hello@pinnashield.com.