Disclosure
If you have found a security problem in SupportCentral Enterprise, we want to hear about it and we will not come after you for telling us.
Last updated: · Applies to SupportCentral Enterprise, operated by Support IT Ventures.
How to report
Email security@supportcentral.in with enough detail to reproduce the issue: the URL, the steps, what you expected and what happened. A proof of concept helps. Please do not post it publicly before we have had a chance to fix it.
What we promise
- We acknowledge every report within 72 hours.
- We tell you our assessment and a target fix date within 7 days.
- We will not take legal action against you for research conducted in line with this policy.
- We will credit you publicly when the fix ships, if you want us to.
In scope
- The application and marketing site on our own domains.
- Authentication, session handling and access control.
- Cross-account data access of any kind — this is the one we care about most.
- Injection, cross-site scripting, request forgery, insecure direct object references.
Out of scope
- Denial of service, volumetric testing and anything that degrades the service for customers.
- Social engineering of our staff or customers, and physical attacks.
- Reports from automated scanners with no demonstrated impact.
- Missing hardening headers with no exploitable consequence, and issues requiring a rooted device or a compromised browser.
What a good report looks like
The reports we can act on fastest say what you did, what you expected, what happened instead, and why it matters. A single screenshot of a scanner result with a severity label rarely helps; a three-line reproduction almost always does.
If you are not sure whether something is a real issue, send it anyway. We would much rather read ten reports that turn out to be intended behaviour than miss the eleventh.
Rules
Test only against an account you control. Do not access, modify or retain another customer's data — if you access some accidentally, stop, tell us, and delete it. Do not run anything that affects availability.
We do not currently run a paid bug bounty. We are a small company; what we offer is a fast, honest response and public credit.
Something here unclear or unfair? Tell us at support@supportcentral.in. We would rather fix the wording than argue about it later. See also Terms, Privacy and Grievance redressal.