Skip to main content
New Download the free Source-to-Pay Buyer's Checklist - get the guide.
Legal

Responsible Disclosure Policy

Effective Date: 15th July 2026

AgileApt Solutions Private Limited takes the security of our website and Product seriously. We value the work of security researchers and the wider community in helping us identify and address vulnerabilities. This Responsible Disclosure Policy explains how to report a security vulnerability to us and what you can expect in return.

See also our product-level Security & Compliance page - this legal policy governs the reporting process itself.

1. Scope

This policy applies to:

  • Our website: https://procurengine.ai
  • Our procurement SaaS Product and its associated production infrastructure, to the extent publicly accessible

It does not apply to third-party services we use (e.g., Cloudflare, Zoho, Google, LinkedIn) - please report vulnerabilities in those platforms directly to the respective vendor.

2. Reporting a Vulnerability

If you believe you have found a security vulnerability, please report it to us at:

Email: security@procurengine.ai

Please include, where possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, including affected URL(s), request/response samples, or proof-of-concept code
  • Any tools used
  • Your contact details, for follow-up questions

3. Our Commitment to You

When you report a vulnerability in good faith and in accordance with this policy, we commit to:

  • Acknowledge receipt of your report within 3 business days
  • Provide an initial assessment/triage within 10 business days
  • Keep you reasonably informed of our progress towards resolution
  • Not pursue or support legal action against you for good-faith research conducted in accordance with this policy
  • Credit your discovery (with your permission) once the issue is resolved, where you wish to be acknowledged

We do not currently offer a paid bug bounty program. Recognition and/or a token of appreciation may be extended at our sole discretion.

4. Ground Rules (Safe Harbor)

To help us protect our users while your research is ongoing, please:

  • Give us reasonable time to investigate and remediate an issue before disclosing it publicly
  • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services
  • Only interact with accounts you own or with explicit permission from the account holder
  • Do not access, download, modify, or delete data that does not belong to you

Activities conducted in good-faith compliance with this policy will be considered authorised, and we will not initiate or support legal action against individuals for such activity.

5. Out of Scope

The following are generally considered out of scope unless you can demonstrate a concrete, exploitable security impact:

  • Denial-of-service (DoS/DDoS) attacks or any testing that degrades service availability
  • Social engineering, phishing, or physical attacks against our employees, users, or offices
  • Spam or content-injection attacks with no security impact
  • Automated vulnerability scanning that generates excessive traffic without prior coordination
  • Reports based solely on outdated browser/software versions, missing security headers, or best-practice recommendations without a demonstrated exploit
  • Vulnerabilities in third-party services not operated by us

6. Confidentiality

Please keep any vulnerability details confidential until we have had a reasonable opportunity to investigate and remediate, and we have mutually agreed on public disclosure (if any).

7. Contact Us

AgileApt Solutions Private Limited
B-821, Advant Navis Business Park, Noida - 201305, Uttar Pradesh, India
Email: security@procurengine.ai

FAQ

Responsible disclosure questions we hear often.

What is responsible disclosure?
It provides a safe route for reporting potential security vulnerabilities.
How do I report a security vulnerability?
Use the contact route on this page to submit a report with enough detail for the security team to reproduce the issue.
Will I get a response after reporting an issue?
Yes. Reports submitted in good faith and within scope receive an acknowledgement and follow-up from the security team.