Responsible Disclosure BLR Pods

Effective from 1st April 2024 Bangalore, Karnataka Bug Bounty Program

Help us keep BLR Pods secure by responsibly reporting security vulnerabilities.

Introduction

At BLR Pods, we take the security of our systems and the privacy of our users seriously. We are committed to maintaining the highest standards of security and appreciate the role that security researchers and the broader security community play in enhancing our security posture. If you have discovered a potential security vulnerability in our systems, we encourage you to disclose it to us responsibly.

Reporting Process

If you believe you have found a security vulnerability on our website or in any of our services, please follow these steps:

  1. Email Us: Send an email with the subject line "Security Vulnerability Report" to support@blrpods.com. Include detailed description, steps to reproduce, and proof of concept.
  2. Include Details: Your report should contain:
    • A description of the vulnerability and its potential impact.
    • The specific URL or part of the website where it can be observed.
    • Detailed steps to reproduce the vulnerability.
    • Relevant screenshots, code snippets, or proof of concept.
    • Your contact information (name, email, optionally phone).
  3. Do Not Disclose Publicly: Please do not share the vulnerability publicly until we have investigated and addressed it.

Our Commitment

When you submit a vulnerability report, we commit to:

  • Acknowledging receipt within 3 business days.
  • Providing an estimated timeframe for resolution.
  • Keeping you informed of our progress.
  • Recognizing your contribution once resolved (if desired).

Scope

In Scope:

Out of Scope:

  • Clickjacking on pages with no sensitive actions.
  • Unauthenticated/logout/login CSRF.
  • Attacks requiring MITM or physical access to user's device.
  • Previously known vulnerable libraries without working PoC.
  • Content spoofing/text injection without HTML/CSS modification.

Safe Harbor

BLR Pods commits to not initiating legal action against researchers who:

  • Test systems without harming BLR Pods, customers, or partners.
  • Make good faith efforts to avoid privacy violations or service disruption.
  • Provide reasonable time for resolution before public disclosure.
  • Do not engage in extortion or coercion.

Recognition

We appreciate security researchers who responsibly disclose vulnerabilities. Contributors will be acknowledged in our Security Hall of Fame if desired.

Security Hall of Fame
Coming soon - recognizing our security researchers

Contact

Security Team: support@blrpods.com
WhatsApp: +91 72051 75999
Response Time: 24-48 hours

Thank you for helping us keep BLR Pods and our users safe.