FREE DPDP GAP ASSESSMENTCheck your DPDP readiness in 5–7 minutes.

Cytrusst
Responsible Disclosure

Help Us Stay Safe & Secure

Cytrusst invites security researchers to responsibly find and report vulnerabilities across our platform. Your discoveries make our GRC, ASM and Cloud Security products stronger for every enterprise we protect.

In Scope*.cytrusst.com
RewardsCertification + Goodies
ResponseWithin 48 hours
ProgramActive & Open
Recognition & Rewards

Reward Tiers

Rewards scale with the severity and impact of your finding. Every valid report earns recognition.

Critical
  • Hall of Fame #1 spotlight
  • Premium goodies pack
High
  • Hall of Fame listing
  • Goodies pack
Medium
  • Hall of Fame Listing
  • Digital certificate
Low
  • Digital certificate
The Process

How to Report

Follow these simple steps to report a vulnerability. We'll take care of the rest.

01

Find & Document

Record the exact steps, capture screenshots, and clearly describe the security impact of the issue.

02

Write a clear PoC

Provide reproducible HTTP requests, payloads, and any code needed to verify the vulnerability.

03

Email your report

Send your complete write-up to both security contacts listed below. We respond within 48 hours.

Report a Vulnerability

Submit a Report

PDF, PNG, JPEG, GIF or WEBP, up to 5 files. 5 remaining.
Researchers Who Made Us Safer

Hall of Fame

ResearcherTargetFindingYearSeverity
Kavin Nagarajapi.cytrusst.comCommand injection2026Critical
Kavin Nagarajapi.cytrusst.comSQL injection2026High
Kavin Nagarajapi.cytrusst.comXSS2026Medium
Kavin Nagarajapi.cytrusst.comCommand injection2026 · Critical
Kavin Nagarajapi.cytrusst.comSQL injection2026 · High
Kavin Nagarajapi.cytrusst.comXSS2026 · Medium
Play Fair

Program Rules

1

Clear, reproducible reports required

Every submission needs steps, a PoC, and a clear impact statement.

2

No aggressive automated scanning

Avoid high-volume scanners and any traffic that degrades service.

3

Test only in-scope targets

Restrict all testing to cytrusst.com and listed assets.

4

No social engineering

Phishing, physical attacks, and targeting staff are out of scope.

Keep findings confidential until fixed. Do not disclose publicly before we confirm a fix has shipped.

Never access, alter, or exfiltrate user data. Use only test accounts.

Terms and Conditions

Responsible Disclosure Terms & Guidelines

By participating in the Cytrusst Responsible Disclosure Program, you agree to the following:

  • Do not modify, delete, or misuse customer or user data without prior written authorization.
  • Do not perform testing that disrupts services or negatively affects other users.
  • Keep all vulnerability information confidential and do not disclose it publicly without Cytrusst's written approval.
  • Do not exploit any discovered vulnerability for personal gain.
  • Immediately notify Cytrusst if any inadvertent exposure of sensitive information occurs.
  • Allow Cytrusst a reasonable amount of time to investigate and remediate reported vulnerabilities before any public disclosure.
  • Comply with all applicable laws and regulations during security research.
  • Provide sufficient technical details, including reproduction steps and proof of concept, to help validate and remediate the issue.
  • Assist with clarification or mitigation if requested by the Cytrusst security team.

Submission of a vulnerability report constitutes acceptance of these Responsible Disclosure Guidelines. Any violation of these terms may result in removal from the program and appropriate legal action where applicable.

Out of Scope Targets

All external services, software, or infrastructure not owned, managed, or controlled by Cytrusst are considered out of scope and are not eligible for recognition.

Vendor Endpoints
Delivery Endpoints
Third-Party Applications
External APIs and Services not owned by Cytrusst

Out of Scope Vulnerabilities — Web

The following issues are considered out of scope unless accompanied by a demonstrable security impact:

  • SPF, DMARC, or DKIM misconfigurations without verifiable email spoofing.
  • Best practice issues such as: Cookies not marked Secure or HttpOnly (when non-sensitive), Missing security headers, SSL/TLS configuration recommendations.
  • Reports generated solely by automated scanners without a valid Proof of Concept.
  • Issues affecting End-of-Life browsers (e.g., Internet Explorer 6).
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
  • Vulnerabilities requiring physical access to a victim's device.
  • Host Header Injection.
  • Unauthenticated, login, or logout CSRF.
  • Reports involving outdated or vulnerable libraries without a working exploit.
  • Email spoofing, phishing attacks, fake login pages, or credential harvesting.
  • Self-XSS.
  • Social engineering attacks requiring unrealistic user interaction.
  • Third-party API keys intended to be public or exposed Android XML keys without security impact.
  • Enabled HTTP OPTIONS or TRACE methods.
  • Disclosure of public files or directories (robots.txt, CSS, images, etc.).
  • Browser autocomplete or password-saving functionality.
  • Vulnerabilities requiring browser extensions or additional software on the victim's device.
  • Brute-force attacks against non-sensitive forms (e.g., Contact Us, Newsletter).
  • Missing Content Security Policy best practices.
  • Missing SSL certificates or CAA records.
  • Functional, UI/UX, cosmetic, or spelling issues.

Cytrusst · Safe & Secure · Bug Bounty Program

© 2026 Cytrusst Intelligence Private Limited. All rights reserved.