Inqevra AI Legal Center
Security and Responsible Disclosure Policy
Security practices, safe vulnerability research, reporting requirements, and coordinated disclosure expectations.
- Effective
- 23 September 2026
- Last updated
- 23 September 2026
- Status
- Pre-launch policy
1. Our security approach
Inquev intends to use layered controls appropriate to the Service, including server-only secrets, least-privilege access, secure sessions, encryption in transit, input validation, rate limiting, logging, monitoring, backups, dependency review, and incident response.
Security is an ongoing process and no system can be guaranteed completely secure. Users should use unique credentials, protect recovery channels, review active sessions, and report suspicious activity promptly.
2. Reporting a vulnerability
Send a concise report to support@technovix.in with “Security report” in the subject. Include the affected URL or component, reproducible steps, impact, supporting evidence, and a safe way to contact you.
Do not include unnecessary personal data, secrets belonging to other users, or publicly disclose an unresolved vulnerability before coordinated remediation.
3. Good-faith research requirements
- Test only accounts, data, and resources you own or have explicit permission to use.
- Stop immediately if you access another person's data, credentials, private content, or payment information, and report only the minimum evidence needed.
- Use the least intrusive method and avoid persistence, lateral movement, data modification, or service disruption.
- Respect rate limits and do not perform denial-of-service testing, spam, mass account creation, broad automated scanning, or destructive payload execution.
- Do not use social engineering, phishing, physical intrusion, employee targeting, or third-party provider attacks.
- Give us reasonable time to investigate and remediate before disclosure.
4. Out-of-scope reports
- Missing best-practice headers without a demonstrated security impact.
- Clickjacking on pages without sensitive actions.
- Self-XSS or attacks requiring a user to paste code without meaningful additional impact.
- Rate-limit observations that do not enable abuse, account compromise, material cost, or service disruption.
- Automated scanner output without manual validation and reproducible impact.
- Known vulnerable-library versions without evidence that the vulnerable path is reachable and exploitable.
- AI prompt manipulation that only changes your own output and does not expose data, cross an authorisation boundary, or perform an unauthorised action.
5. Our response
We aim to acknowledge credible reports, investigate severity, communicate material progress, and coordinate remediation. Response timing depends on complexity, provider involvement, legal obligations, and risk. This Policy does not promise a bounty or payment.
Where research follows this Policy and applicable law, we will not intentionally pursue action solely for the good-faith testing described here. This is not permission to violate law, third-party rights, provider terms, or systems outside our control.
6. Security incidents and account concerns
For suspected account compromise, unauthorised payment, exposed personal data, or an active incident, contact support@technovix.in immediately and include a safe callback method. Do not send passwords, OTPs, CVVs, recovery codes, or full payment credentials.
