Responsible Disclosure
We welcome good-faith reports that help improve the security of Moonera-owned systems, subject to this policy and explicit scope.
General enquiries may be sent to hello@moonera.in. Privacy and security contacts are listed in the relevant sections. Contract notices follow the accepted service order.
Scope
Only assets explicitly confirmed in writing by Moonera are in scope. Third-party services, client systems, social engineering, denial-of-service testing, physical attacks and access to other people's data are excluded unless specifically authorised.
Research rules
- Use the minimum testing needed to demonstrate the issue.
- Do not retain, alter, delete or publicly disclose accessed data.
- Stop and report immediately if sensitive or third-party data is encountered.
- Do not disrupt availability or degrade service.
- Give Moonera reasonable time to investigate before any disclosure discussion.
What to include
Email security@moonera.in with the affected asset, clear reproduction steps, impact, supporting evidence and a safe way to contact you. Encrypt sensitive reports where a key has been published.
Response and rewards
We aim to acknowledge useful reports, but response times are not guaranteed. This policy does not promise payment or a bug-bounty reward. Any recognition or reward is entirely discretionary unless a separate programme states otherwise.