At Mindtickle, we are committed to protecting the privacy and security of the data our customers have entrusted to us. We have implemented numerous measures to secure our infrastructure and the platform.
Despite the measures, due to evolving nature of the technology landscape, it is always possible that we are affected by new vulnerabilities. We acknowledge the importance of time spent and valuable assistance provided by independent security researchers to make our web experience more secure.
We are promoting a culture of responsible disclosure of vulnerabilities that affects the security and privacy of our platform and its users.
The sites, applications, and APIs covered in this policy are listed below.
We have carefully chosen the exclusions to prioritize our remediation efforts on the vulnerability that can be exploited and directly impact our platform hosting customer data. We request you not to report any vulnerabilities that only focus on the enumeration and information gathering and have no potential to penetrate our systems. Anything not declared in the scope above is considered out of scope.
The below list covers the exclusions –
We encourage the efforts spent by security researchers to identify legitimate vulnerabilities. To make this process smooth, we have defined a set of guidelines that help us differentiate malicious intent from the genuine discovery that helps us make our platform safer.
If you have found any in scope security or privacy vulnerability and adhere to the exclusions and guidelines, please report it to us promptly by emailing it to the Mindtickle security team at [email protected]. We ask that you do not share any of the details of the identified vulnerability publicly or with anyone else apart from the Mindtickle security team.
Include the following details with your report:
We will get back to you as soon as possible and keep you updated on the progress of the vulnerability remediation activity.
If you comply with this policy while reporting the vulnerability, we will safeguard you against any legal action under Computer Fraud and Abuse Act (CFAA) or Digital Millennium Copyright Act (DMCA).
We extend our sincere gratitude to the following security researchers who contributed to strengthening Mindtickle’s security posture through our Responsible Vulnerability Disclosure Policy. Your collective efforts in identifying and assisting with vulnerability remediation are vital to protecting our customers and building a more secure platform.
Researcher Name | Social Profile / Email | Number of Reports |
Armaan Sidana | 1 | |
Rishyendra M | 1 | |
Akash Singh | 1 | |
Ambika Dave | 1 | |
Ayush Kumar | 1 | |
A Sai Vardhan | 1 | |
Nikhil Chaudhari | 1 | |
Sheetal Sangle | 1 | |
Mohd Ali | 1 | |
Gaurang Maheta | 2 | |
Yogeswaran M | 1 | |
Navaneethan M | 1 | |
Shivam Dhingra | 1 | |
Ali Raza | 1 | |
Vinayak Sakhare | 1 | |
Rahul Karki | X(Twitter) | 1 |
Sumit Sahoo | Website | 2 |
Foysal Ahmed Fahim | X(Twitter) | 1 |
Devansh Chauhan | 1 | |
Pushkar Vyas | 1 | |
Gaurav Shukla (Ciphershade) | 1 | |
Zain Iqbal | 5 |
© 2024 Mindtickle Inc. All rights reserved.