Security

Security & responsible disclosure.

Effective: August 2026 Entity: Rigene Ventures Pvt. Ltd. Contact: security@rigeneventures.com
이 페이지는 영문으로만 제공됩니다. 영문본이 기준이 됩니다. English ›

01 — Reporting a vulnerability

Tell us before you tell anyone else

If you believe you have found a security vulnerability in any system operated by Rigene Ventures Private Limited, write to security@rigeneventures.com. Please include enough detail for us to reproduce the issue — the affected URL or endpoint, the steps taken, and any proof-of-concept output.

Machine-readable contact details are published at /.well-known/security.txt in line with RFC 9116.

We ask that you give us a reasonable period to remediate before any public disclosure, and that you do not access, modify, or retain data belonging to anyone other than yourself.

02 — Scope

Systems covered

  • www.rigeneventures.com — this corporate website and its subdomains
  • Email infrastructure operating under the rigeneventures.com domain, including SPF, DKIM and DMARC configuration
  • Publicly reachable services operated by Rigene Ventures Private Limited or its brands, where those services are not covered by a separate disclosure programme

03 — Safe harbour

Good-faith research is welcome

Where research is conducted in good faith and in accordance with this policy, Rigene Ventures will not pursue civil action or initiate a complaint to law enforcement. We will treat your research as authorised access, and we will work with you to understand and resolve the issue quickly.

This protection applies only where you avoid privacy violations, service degradation, data destruction, and disruption to others, and where you stop testing and report immediately upon encountering personal data.

04 — Out of scope

Reports we will close without action

  • Missing security headers with no demonstrated exploit path
  • Reports generated solely by automated scanners without validation
  • Volumetric denial-of-service, load testing, or resource-exhaustion testing
  • Social engineering, phishing, or physical attacks against our staff or offices
  • Vulnerabilities in third-party services we do not operate
  • Theoretical issues without a realistic attack scenario

05 — Our response commitment

What you can expect from us

  • Acknowledgement within three business days of receipt
  • Initial assessment and severity triage within ten business days
  • Progress updates at reasonable intervals until the issue is resolved
  • Notification when a fix is deployed, together with credit where you want it

06 — How we protect this site

Controls in place

This website is a static corporate information portal. It processes no payments, hosts no user accounts, and operates no login. The following controls apply:

  • TLS enforced site-wide with HTTP Strict Transport Security and preload
  • A strict Content Security Policy with no inline script or style execution and no third-party origins permitted
  • X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and cross-origin isolation headers set on every response
  • No third-party trackers, advertising pixels, or analytics scripts
  • Request rate limiting at the edge, and no server-side write paths

07 — Recognition

Credit, not bounty

Rigene Ventures does not currently operate a paid bug bounty programme. We do offer public acknowledgement to researchers who report valid issues responsibly, and we are glad to provide a written reference confirming your contribution.

Questions about this policy: security@rigeneventures.com. Legal or compliance queries: legal@rigeneventures.com.

Postal reports may be sent to Rigene Ventures Private Limited, 39/2475-B1, Suite 249, LR Towers, SJRRA 104, South Janatha Road, Palarivattom, Ernakulam, Kerala, India — 682025.