LEGAL

Responsible Disclosure Policy

Last updated: 25 June 2026

At Varihunt, we take the security of our systems and our clients' systems seriously. We value the contributions of security researchers and appreciate responsible disclosure of potential vulnerabilities.

Scope

This policy applies to the Varihunt website (varihunt.com) and any digital infrastructure we directly own and operate. It does not apply to client systems or environments — those are covered by separate engagement agreements.

Guidelines

If you believe you have found a security vulnerability, we ask that you:

  • Report it to us promptly at security@varihunt.com.
  • Provide sufficient detail to reproduce the issue, including steps, tools used, and observed impact.
  • Do not access, modify, or destroy data that does not belong to you.
  • Do not attempt denial-of-service, brute force, or social engineering attacks.
  • Do not publicly disclose the vulnerability until we have had reasonable time to investigate and remediate.
  • Act in good faith and avoid privacy violations or disruption to our services.

What we commit to

We will acknowledge receipt of your report within 2 business days. We will investigate the report and keep you informed of progress. If the vulnerability is confirmed, we will work to remediate it and credit you (if you wish) once the issue is resolved.

Safe harbour

We will not take legal action against researchers who make a good-faith effort to report vulnerabilities in accordance with this policy, provided their actions do not cause harm to our systems, our users, or our clients.

Contact

Send all vulnerability reports to security@varihunt.com. For encrypted communication, request our PGP key at the same address.