Security Disclosure Policy
Last updated: 26 September 2026.
Security is our work, so we take it seriously in our own systems too. If you believe you have found a security vulnerability in a VA2PT (Batif Services Pvt Ltd) system, we want to hear from you.
How to report
Email sales@va2pt.com with the subject line "Security disclosure". Please include:
- A clear description of the issue and where you found it.
- The steps to reproduce it, or a proof of concept.
- The potential impact as you see it.
- How we can reach you for follow-up.
Our commitment
- We aim to acknowledge your report within three business days and to keep you updated as we investigate.
- We will work to validate and fix confirmed issues promptly, based on severity.
- We are happy to credit researchers who report valid issues responsibly, if you would like to be named.
Safe harbour
We will not pursue or support legal action against anyone who, in good faith:
- Reports a vulnerability through the channel above.
- Avoids privacy violations, data destruction, and any degradation of our services.
- Does not access, modify or retain more data than is necessary to demonstrate the issue, and deletes any such data after reporting.
- Gives us a reasonable time to remediate before any public disclosure.
Please make a good-faith effort to avoid disrupting services or accessing others' data. Testing must stay within systems that VA2PT operates.
Out of scope
Reports that describe theoretical issues without a realistic security impact, volumetric or denial-of-service testing, social engineering of our staff, and findings in third-party services we do not control are generally out of scope. When in doubt, email us and ask.
For our clients
Vulnerabilities in systems we operate on behalf of a client are handled through that client's agreed reporting and escalation process, including any obligations under India's CERT-In directions. If you are unsure who to contact, email us and we will route it correctly.