HomeProductsAIServicesIntegrationsCompany

Security & Disclosure

01Report a vulnerability

Email [email protected], or [a dedicated security@ mailbox is better — confirm whether one exists]. Include enough detail to reproduce the issue: affected asset, steps, impact, and any proof-of-concept.

Purplecop operates a coordinated disclosure process and welcomes participation from security researchers.

[publish a PGP key for encrypted reports, and a security.txt file at /.well-known/security.txt]

02What we commit to

[do you run a paid bug bounty? If not, say so explicitly here — an unstated answer reads as yes]

  • Acknowledgement within 24 hours of your report.
  • Critical issues resolved within 48 hours.
  • A triage decision and severity rating within [triage SLA for non-critical reports].
  • Regular updates until the issue is resolved, and a monthly security bulletin covering threats, patches and recommendations.
  • Credit in our advisory if you want it, and no legal action against good-faith research under this policy.

03Scope

In scope: [list the production domains and platform hostnames in scope]

Out of scope: denial of service and volumetric testing, social engineering of our staff or customers, physical attacks, spam or automated scanner output with no demonstrated impact, and any testing against a customer tenant that is not your own.

04Rules for testing

  • Use only your own accounts and test data.
  • Do not access, modify or exfiltrate anyone else’s data. If you encounter personal data, stop and tell us.
  • Do not degrade the service for other users.
  • Give us reasonable time to fix an issue before disclosing it publicly — we suggest [disclosure window, e.g. 90 days].

05Incident response

We run a documented incident response process with defined severities, an on-call rotation and post-incident review. Where an incident affects customer data we notify affected customers [customer notification SLA] and, where the law requires it, regulators — under the DPDPA that means the Data Protection Board of India and each affected Data Principal.

Our own SOC monitors the products, on the same 24/7 basis we sell to customers.