Responsible Security Disclosure Policy

Version 1.0 · Effective date: 21 September 2026 · Last updated: 21 September 2026

Legal entity
Kenstone Capital Debt Consulting Private Limited (CIN U67200KA2019PTC124970), operating under the brand name "Kenstone Capital" ("Kenstone", "we").
Scope
security vulnerabilities in https://www.kenstonecapital.in and in systems Kenstone operates that are reachable from the internet. It does not cover systems of our clients, our group companies or our service providers, which have their own policies.
Machine-readable version
https://www.kenstonecapital.in/.well-known/security.txt

1. What we ask

If you believe you have found a security vulnerability that affects Kenstone, tell us privately before telling anyone else, and give us a reasonable time to fix it. We will treat your report seriously and in confidence.

2. How to report

Email info@kenstonecapital.in with the subject "Security report". Include: the affected address or system; a description of the issue and its likely impact; steps to reproduce, with screenshots or a proof-of-concept that demonstrates the issue without exploiting it; your contact details, and whether you would like to be credited. Please do not send personal data you may have encountered; describe its type instead.

3. What you must not do

  • Do not access, copy, download, modify or delete data that is not your own. If you encounter client, debtor or personal data, stop, note the type, and report it.
  • Do not disrupt the service: no denial-of-service, load testing, spamming of forms, or automated scanning at a rate that affects availability.
  • Do not use social engineering, phishing or physical intrusion against our staff, offices or providers.
  • Do not test third-party systems (Cloudflare, Google, our telephony or e-signature providers) under this policy.
  • Do not demand payment as a condition of disclosure. We do not run a paid bounty programme at present.
  • Do not publish the vulnerability before we confirm it is fixed or 90 days have passed, whichever is earlier, unless we agree otherwise.

4. What we will do

  • Acknowledge your report within 3 working days.
  • Assess it and tell you our view of its severity within 10 working days.
  • Keep you informed of progress and tell you when it is fixed.
  • Credit you publicly on request, once fixed, if you wish.
  • Not pursue legal action against a researcher who acts in good faith within this policy and the Information Technology Act, 2000.

5. Out of scope

Reports about missing best-practice headers with no demonstrable impact, clickjacking on pages without sensitive actions, software version disclosure, email configuration (SPF/DKIM/DMARC) unless exploitable, and issues on pages we do not control are welcome but are not treated as vulnerabilities.

6. Our own obligations

Kenstone reports cyber-security incidents to the Indian Computer Emergency Response Team (CERT-In) within the time its directions of 28 April 2022 require, keeps system logs for the period they require, and notifies affected persons and the Data Protection Board of India of personal-data breaches as the Digital Personal Data Protection Rules, 2025 require. A researcher's report does not itself make an incident reportable; our assessment does.

7. Contact

info@kenstonecapital.in (subject: "Security report") · Kenstone Capital Debt Consulting Private Limited, Sabari Complex, Field Marshal Cariappa Road, Shanthala Nagar, Ashok Nagar, Bengaluru 560025.

Earlier versions of this document are available on request from info@kenstonecapital.in. Questions or complaints: Grievance Redressal Policy.

CallWhatsAppEnquire