Skip to contentFounder TierPioneer Founder · ₹499/month · limited to the first 100Claim a spot

Security Policy

At Indian Venture Labs, we take the security of our platform and user data seriously. This page outlines how to responsibly disclose security vulnerabilities.

Responsible Disclosure

If you believe you've discovered a security vulnerability in our platform, we encourage you to report it responsibly. We appreciate your help in keeping Indian Venture Labs safe for everyone.

Please report vulnerabilities via email to hello@indianventurelabs.ai

What We Ask

  • Give us reasonable time to fix the issue before public disclosure (90 days)
  • Do not access, modify, or delete other users' data
  • Do not perform denial-of-service attacks
  • Do not use automated scanning tools that generate excessive traffic
  • Provide sufficient detail to reproduce the vulnerability
  • Act in good faith to avoid privacy violations and service disruption

In Scope

indianventurelabs.ai (production)
Authentication & session management
API endpoints (/api/*)
Data access controls
Cross-site scripting (XSS)
SQL/NoSQL injection
Server-side request forgery (SSRF)
Privilege escalation

Response Timeline

24 hoursAcknowledgement of your report
72 hoursInitial assessment and severity classification
14 daysStatus update on the fix
90 daysTarget resolution window

Contact

For security-related reports, please email:

hello@indianventurelabs.ai

For non-security inquiries, please use our in-app feedback or contact support.

This policy follows RFC 9116. Our security.txt file is available at /.well-known/security.txt