Responsible Security Disclosure Policy
Version 1.0 · Effective date: 21 September 2026 · Last updated: 21 September 2026
1. What we ask
If you believe you have found a security vulnerability that affects Kenstone, tell us privately before telling anyone else, and give us a reasonable time to fix it. We will treat your report seriously and in confidence.
2. How to report
Email info@kenstonecapital.in with the subject "Security report". Include: the affected address or system; a description of the issue and its likely impact; steps to reproduce, with screenshots or a proof-of-concept that demonstrates the issue without exploiting it; your contact details, and whether you would like to be credited. Please do not send personal data you may have encountered; describe its type instead.
3. What you must not do
- Do not access, copy, download, modify or delete data that is not your own. If you encounter client, debtor or personal data, stop, note the type, and report it.
- Do not disrupt the service: no denial-of-service, load testing, spamming of forms, or automated scanning at a rate that affects availability.
- Do not use social engineering, phishing or physical intrusion against our staff, offices or providers.
- Do not test third-party systems (Cloudflare, Google, our telephony or e-signature providers) under this policy.
- Do not demand payment as a condition of disclosure. We do not run a paid bounty programme at present.
- Do not publish the vulnerability before we confirm it is fixed or 90 days have passed, whichever is earlier, unless we agree otherwise.
4. What we will do
- Acknowledge your report within 3 working days.
- Assess it and tell you our view of its severity within 10 working days.
- Keep you informed of progress and tell you when it is fixed.
- Credit you publicly on request, once fixed, if you wish.
- Not pursue legal action against a researcher who acts in good faith within this policy and the Information Technology Act, 2000.
5. Out of scope
Reports about missing best-practice headers with no demonstrable impact, clickjacking on pages without sensitive actions, software version disclosure, email configuration (SPF/DKIM/DMARC) unless exploitable, and issues on pages we do not control are welcome but are not treated as vulnerabilities.
6. Our own obligations
Kenstone reports cyber-security incidents to the Indian Computer Emergency Response Team (CERT-In) within the time its directions of 28 April 2022 require, keeps system logs for the period they require, and notifies affected persons and the Data Protection Board of India of personal-data breaches as the Digital Personal Data Protection Rules, 2025 require. A researcher's report does not itself make an incident reportable; our assessment does.
7. Contact
info@kenstonecapital.in (subject: "Security report") · Kenstone Capital Debt Consulting Private Limited, Sabari Complex, Field Marshal Cariappa Road, Shanthala Nagar, Ashok Nagar, Bengaluru 560025.
Earlier versions of this document are available on request from info@kenstonecapital.in. Questions or complaints: Grievance Redressal Policy.

