01 — Reporting a vulnerability
Tell us before you tell anyone else
If you believe you have found a security vulnerability in any system operated by Rigene Ventures Private Limited, write to security@rigeneventures.com. Please include enough detail for us to reproduce the issue — the affected URL or endpoint, the steps taken, and any proof-of-concept output.
Machine-readable contact details are published at /.well-known/security.txt in line with RFC 9116.
We ask that you give us a reasonable period to remediate before any public disclosure, and that you do not access, modify, or retain data belonging to anyone other than yourself.
02 — Scope
Systems covered
- www.rigeneventures.com — this corporate website and its subdomains
- Email infrastructure operating under the rigeneventures.com domain, including SPF, DKIM and DMARC configuration
- Publicly reachable services operated by Rigene Ventures Private Limited or its brands, where those services are not covered by a separate disclosure programme
03 — Safe harbour
Good-faith research is welcome
Where research is conducted in good faith and in accordance with this policy, Rigene Ventures will not pursue civil action or initiate a complaint to law enforcement. We will treat your research as authorised access, and we will work with you to understand and resolve the issue quickly.
This protection applies only where you avoid privacy violations, service degradation, data destruction, and disruption to others, and where you stop testing and report immediately upon encountering personal data.
04 — Out of scope
Reports we will close without action
- Missing security headers with no demonstrated exploit path
- Reports generated solely by automated scanners without validation
- Volumetric denial-of-service, load testing, or resource-exhaustion testing
- Social engineering, phishing, or physical attacks against our staff or offices
- Vulnerabilities in third-party services we do not operate
- Theoretical issues without a realistic attack scenario
05 — Our response commitment
What you can expect from us
- Acknowledgement within three business days of receipt
- Initial assessment and severity triage within ten business days
- Progress updates at reasonable intervals until the issue is resolved
- Notification when a fix is deployed, together with credit where you want it
06 — How we protect this site
Controls in place
This website is a static corporate information portal. It processes no payments, hosts no user accounts, and operates no login. The following controls apply:
- TLS enforced site-wide with HTTP Strict Transport Security and preload
- A strict Content Security Policy with no inline script or style execution and no third-party origins permitted
X-Content-Type-Options,X-Frame-Options,Referrer-Policy,Permissions-Policyand cross-origin isolation headers set on every response- No third-party trackers, advertising pixels, or analytics scripts
- Request rate limiting at the edge, and no server-side write paths
07 — Recognition
Credit, not bounty
Rigene Ventures does not currently operate a paid bug bounty programme. We do offer public acknowledgement to researchers who report valid issues responsibly, and we are glad to provide a written reference confirming your contribution.
Questions about this policy: security@rigeneventures.com. Legal or compliance queries: legal@rigeneventures.com.
Postal reports may be sent to Rigene Ventures Private Limited, 39/2475-B1, Suite 249, LR Towers, SJRRA 104, South Janatha Road, Palarivattom, Ernakulam, Kerala, India — 682025.