Security and Responsible Disclosure
How e10 Infotech protects information, how to report a vulnerability, what we ask you to avoid while testing, our response times, safe harbour and breach notification.
Last updated: 29 July 2026. This version replaces all earlier versions.
This security policy describes how e10 Infotech Private Limited protects information, and how to report a vulnerability to us. We would rather hear about a weakness from you than read about it later, so this page sets out a route that is safe for both sides.
Scope
This covers the e10 Infotech website and the systems we operate for our own business. Systems we built for a client but that the client hosts and controls are the client responsibility, and disclosure should go to them. If you are unsure who owns something, report it to us and we will route it or tell you who to contact.
How we protect information
- Access to systems and client environments is granted on a need to know basis and reviewed when roles change
- Data is encrypted in transit, and at rest where the platform supports it
- Staff and contractors are bound by confidentiality obligations, and are removed from access when an engagement ends
- Production, staging and development environments are kept separate, and production personal data is not copied into staging or demo environments
- Secrets and credentials are held in managed secret storage rather than in source code or shared documents
- Dependencies are monitored and patched, and we track advisories for the frameworks we build on
- Changes reach production through review, with logging and the ability to roll back
- Devices used for client work require disk encryption, screen lock and current operating system patches
- Backups are taken for the systems we host, and restore is tested rather than assumed
We describe practices here rather than claiming a certification we do not hold. If you need a specific control framework, an audit response or a security questionnaire completed for a procurement process, ask us and we will answer honestly about what we do and do not have.
Reporting a vulnerability
Email hello@e10infotech.com with the subject line beginning Security. Please include:
- The URL, endpoint, parameter or component affected
- What you did, in enough detail that we can reproduce it
- What you observed, and why you think it is a problem
- Any screenshots, request and response captures, or a short proof of concept
- How you would like to be credited, if you would like credit
Report in English. One issue per report is easier for everyone. If the issue is serious, say so in the first line.
While you are testing, please do not
- Access, modify, delete or download data that does not belong to you, and stop as soon as you confirm access is possible
- Run denial of service or load tests, brute force, or spam our forms and inboxes
- Use automated scanners against production in a way that degrades service for others
- Attempt social engineering or phishing against our staff, clients or suppliers
- Attempt physical access to our office or equipment
- Pivot to a client environment, or to any third party system
- Publish the issue, or share it with anyone else, before we have had a reasonable chance to fix it
- Demand payment in exchange for withholding disclosure
What we will do
We acknowledge a report within three working days. We tell you whether we can reproduce it, and give an initial assessment, normally within ten working days. We keep you informed while we work on a fix, and we tell you when it is deployed. We aim to resolve high severity issues quickly and to agree a realistic timeline with you for anything lower. Where the issue affects a client system we host, we notify that client.
Safe harbour
If you make a good faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorised testing. We will work with you if a third party raises a concern about activity we asked for. Good faith means you stayed within the limits above, you gave us reasonable time, and you did not exploit the issue beyond what was needed to demonstrate it. This is not a bug bounty programme and we do not offer payment. We are glad to credit you publicly if you want that.
Out of scope
Reports we generally close without action include missing security headers with no demonstrated impact, results from an automated scanner with no working proof of concept, issues that need a rooted device or a browser extension the user installed, self inflicted cross site scripting, rate limiting on non sensitive endpoints, version disclosure alone, best practice suggestions with no exploit path, and email configuration findings on domains that do not send mail.
If something goes wrong
If a security incident affects personal data we are responsible for, we investigate, contain, and notify the people and authorities the law requires within the timeframes it sets, including the Data Protection Board of India where the Digital Personal Data Protection Act 2023 applies. Where the incident affects a client environment, that client is notified so they can meet their own obligations. Our handling of personal data is described in the privacy policy.
How to contact us
e10 Infotech Private Limited
B-110, Bhoomi Hills, Thakur Village, Kandivali East, Mumbai, Maharashtra, India 400101
- General enquiries: hello@e10infotech.com
- Privacy and data requests: privacy@e10infotech.com
- Phone: +91 86574 40720
You can also reach us through the contact page.
Frequently asked questions
How do I report a security vulnerability to e10 Infotech?
Email hello@e10infotech.com with a subject line beginning Security, and include the affected URL, reproduction steps, what you observed and any proof of concept.
Do you pay a bug bounty?
No. This is a responsible disclosure programme rather than a paid bounty. We are happy to credit you publicly if you would like that.
Will you take legal action against me for testing?
Not if you acted in good faith within the limits of this policy. We treat compliant research as authorised and will not pursue or support action against you.
How quickly will you respond?
We acknowledge within three working days and aim to give an initial assessment within ten working days, then keep you informed until a fix is deployed.
Can I test a website you built for one of your clients?
Not under this policy. If the client hosts and controls it, report it to them. If you are unsure who owns it, tell us and we will route it.
What should I avoid doing while testing?
Do not access other people data, run denial of service or brute force, use scanners that degrade service, attempt phishing or physical access, or pivot to client systems.
Can I publish my findings?
Please give us a reasonable chance to fix the issue first, then we are happy for you to write it up. Coordinated disclosure protects users.
Do you hold ISO 27001 or SOC 2 certification?
This page describes our practices rather than claiming a certification. Ask us and we will answer honestly about what we hold and complete your security questionnaire.
What kinds of reports do you usually close without action?
Scanner output without a proof of concept, missing headers with no demonstrated impact, version disclosure alone, self inflicted issues, and best practice suggestions with no exploit path.
Is production customer data used in staging environments?
No. Production and non production environments are kept separate and production personal data is not copied into staging or demo environments.
What happens if there is a data breach?
We investigate and contain it, then notify affected people and the authorities the law requires, including the Data Protection Board of India where applicable, and we tell any affected client.
Can you complete our vendor security questionnaire?
Yes. Send it through the contact page or to hello@e10infotech.com and we will complete it, including where a control is not yet in place.