Home/Legal/Responsible Disclosure

Responsible Disclosure

Guidelines for good-faith security research on this website, and how to report what you find.

Last updated: 17 September 2026

Bharat Homeland Security (“BHS”) welcomes reports from security researchers acting in good faith. This policy sets out what we consider good-faith research on this website, what is out of scope, and how to reach us.

Good-faith guidelines

  • Work only within the scope set out below.
  • Do only what is necessary to demonstrate an issue. Stop as soon as you have enough to report it.
  • Do not access, modify, copy or delete data that is not yours, and do not interfere with other people's use of the site.
  • If you encounter personal or confidential information, stop immediately, do not retain it, and tell us in your report.
  • Give us a reasonable opportunity to investigate and remediate before disclosing anything publicly, and please coordinate any publication with us.
  • Comply with applicable law at all times.

In scope

The public website at www.bharathomelandsecurity.com and the pages it serves. Examples of issues we want to hear about include flaws that could expose information, allow content to be altered, or allow visitors to be misled or redirected.

Out of scope

  • Social engineering of BHS personnel, partners, customers or suppliers, and phishing of any kind.
  • Denial-of-service testing, stress or load testing, and anything else intended to degrade availability.
  • Physical testing of premises, people or equipment.
  • Accessing, attempting to access, or exfiltrating data belonging to other people or organizations.
  • Testing systems that are not ours, including third-party hosting or infrastructure providers.
  • Automated scanning that generates significant traffic, and spam or volumetric submissions through contact routes.
  • Reports that consist only of scanner output, missing best-practice headers or theoretical findings without demonstrated impact.

How to report

Email hriday.agm23@iimshillong.ac.in with the subject “Security report”. Please include:

  • What you found and why it matters.
  • The URLs or components affected.
  • Clear steps to reproduce it.
  • Anything you observed that we should know about, including timing.
  • How you would like to be credited, if you would like to be.

Please do not include third-party data in your report. We will acknowledge reports we receive and will keep you informed as we investigate.

What we offer in return

We do not operate a bug-bounty programme and we do not offer payment for reports. We will not pursue action against researchers who follow this policy in good faith. If a report leads to a fix, we are glad to credit you where you would like us to.

Other reports

For security matters that are not research findings on this website — suspected misuse of the BHS name, a security concern about correspondence you have received, or anything similar — see Security Reporting.

Governing law

This policy is governed by the laws of India.