Security

Responsible Disclosure

Last updated: 7 July 2026

Security is our craft, so we hold our own systems to the same standard. If you believe you have found a security vulnerability in dedcellsecurity.in or any asset we own, we want to hear from you and we will work with you to resolve it.

Scope

This policy applies to the website dedcellsecurity.in and infrastructure clearly owned and operated by Dedcell Security. Client systems are strictly out of scope and must never be tested.

Guidelines

  • Act in good faith and avoid privacy violations, data destruction, or service disruption.
  • Only interact with accounts you own or have explicit permission to access.
  • Give us a reasonable opportunity to remediate before any public disclosure.
  • Do not use automated tooling in a way that degrades our services.

Out of Scope

Denial-of-service attacks, social engineering, physical attacks, spam, and reports from automated scanners without a demonstrable, exploitable impact are out of scope.

Safe Harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorized, will not pursue legal action against you, and will work with you to understand and resolve the issue quickly.

How to Report

Email dedcellsec@gmail.com with a clear description of the issue, the affected URL or component, and steps to reproduce (a proof of concept helps). We aim to acknowledge reports within a few business days and will keep you updated on remediation.

Recognition

We do not currently run a paid bug-bounty program, but we are glad to publicly credit researchers who report valid issues, with your permission.