Operator: Adaptive Agility LLC ("Sutradhar", "we", "us", "our"). Security contact: security@adaptiveagility.com
Adaptive Agility LLC is dedicated to preserving the security of the data Sutradhar stewards, and to preventing unauthorized disclosure of information. This policy provides security researchers with instructions for conducting vulnerability discovery activities and explains how to report discovered vulnerabilities to us. It defines which systems and types of activity are covered, how to send vulnerability reports, and how long we ask you to wait before public disclosure.
We request that you:
Security research carried out in conformity with this policy is deemed authorized. We will work with you to swiftly understand and resolve the issue, and Adaptive Agility LLC will not recommend or pursue legal action in connection with research conducted in good faith within this policy.
This policy applies to the following systems and services:
Any service not explicitly listed above is out of scope and is not authorized for testing. Vulnerabilities discovered in third-party platforms Sutradhar builds on (including Google, Microsoft, Anthropic, Render, GoDaddy, and Cloudflare) are not covered by this policy and should be reported directly to the relevant vendor under their own disclosure policy. If you are unsure whether a system or endpoint is in scope, email us at security@adaptiveagility.com before beginning.
To report a security flaw, email security@adaptiveagility.com. We will acknowledge receipt of your report within 2 business days and keep you updated on our progress. Reports may be submitted anonymously.
To help us process and react to your report, we recommend including:
If possible, please provide your report in English.
If you choose to share your contact information, we promise to communicate with you in a transparent and timely manner. We will acknowledge receipt of your report within 2 business days, keep you informed on vulnerability confirmation and remediation to the best of our capabilities, and credit good-faith researchers on request. We welcome discussion of any concerns and are willing to engage in dialogue.