Purpose

Freshtiq Innovations OPC Private Limited welcomes good-faith reports of security vulnerabilities in our public websites, portals and automation systems. This policy explains what researchers may test, what is out of scope, and how to report findings.

What you may report

  • Cross-site scripting (XSS), SQL injection, CSRF, or broken access control on public endpoints.
  • Authentication or session-management weaknesses.
  • Information disclosure of customer or company data through public pages/APIs.
  • Misconfigurations that expose sensitive data or services.

Out of scope

  • Social engineering, phishing, or physical attacks against staff or customers.
  • Denial-of-service, brute-force, or other disruptive testing.
  • Any attempt to access, modify or exfiltrate customer data, credentials, or payment information.
  • Testing of third-party services we use (hosting, payment gateways, messaging platforms).

Rules of engagement

  • Only test accounts and data you own, or clearly marked test environments.
  • Stop testing and report immediately if you encounter customer data or credentials.
  • Do not publicly disclose a vulnerability before we have had a reasonable opportunity to fix it.

How to report

Email details to hello@freshtiqautomation.com. Please include:

  • Affected URL or endpoint, and the date/time of testing.
  • A clear description of the vulnerability and its impact.
  • Minimal reproduction steps (no payloads that damage data).

What to expect

We acknowledge reports within 5 business days and aim to keep you informed of remediation progress. We do not provide monetary rewards for vulnerability reports at this time.

💬 WhatsApp 📱 Telegram 📩 Get Quote
💬💬 🤖