Responsible Disclosure Policy
We welcome security researchers who help us keep the Service safe.
Phronesis AI Lab Private Limited values the security community. This policy explains how to report vulnerabilities in Social Media Digital Marketer ("the Service") and what you can expect from us.
1. How to report
Email [email protected] with a clear description, steps to reproduce, affected endpoints or components, and any proof-of-concept. Please encrypt sensitive details on request and do not disclose the issue publicly until we have resolved it.
2. Our commitment
- We will acknowledge your report within 3 business days.
- We will provide a triage assessment and expected timeline where possible.
- We will keep you informed of remediation progress.
- We will credit reporters who wish to be acknowledged, once the issue is fixed.
3. Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will not pursue or support legal action against you for that research, and we will consider it authorised under applicable computer-misuse laws. This safe harbour does not extend to actions that violate the law or this policy, or that harm users or data.
4. Scope
In scope
- The Social Media Digital Marketer web application and its APIs.
- Authentication, authorisation, and data-handling flaws.
- Vulnerabilities that could expose customer data or connected-account tokens.
Out of scope
- Third-party services and social networks (report to those providers directly).
- Denial-of-service, volumetric, or automated stress testing.
- Social engineering, phishing, or physical attacks against staff or offices.
- Reports from automated scanners without a demonstrated, exploitable impact.
5. Rules of engagement
- Only test against your own accounts and data.
- Do not access, modify, or delete other users' data.
- Stop and report immediately if you encounter customer data.
- Do not exfiltrate data, degrade the Service, or use findings for any purpose other than reporting.
6. Contact
Security team: [email protected].
Last updated: 20 September 2026.