Security at Misar AI
We value the work of security researchers. If you believe you have found a vulnerability in any Misar AI product or service, we want to hear from you — and we commit to working with you in good faith.
Last updated: July 5, 2026
How to Report a Vulnerability
Email your report to our security team. Encrypt sensitive details where possible and include everything we need to reproduce the issue.
Report by email
legal@misar.io — the same contact published in our security.txt.
A good report includes
- -The affected product, domain, or API endpoint and the type of vulnerability (e.g. XSS, IDOR, SSRF, auth bypass).
- -Step-by-step reproduction instructions, including any request/response samples or proof-of-concept code.
- -The impact you believe the issue has, and any suggested remediation.
- -How you would like to be credited (or that you prefer to remain anonymous).
What to Expect From Us
We take every report seriously and commit to the following response targets:
Acknowledgement
We will acknowledge receipt of your report within 72 hours.
Triage & Assessment
We will assess severity and confirm or decline the finding within 7 business days.
Remediation Updates
We will keep you informed of progress until the issue is resolved.
We ask that you give us a reasonable opportunity to remediate a confirmed vulnerability before any public disclosure. We will coordinate a disclosure timeline with you — typically within 90 days of triage.
Scope
This policy covers all production services operated by Misar AI Technology Private Limited.
In scope
- -misar.io, www.misar.io, id.misar.io, tools.misar.io, docs.misar.io
- -api.misar.io (all product API slugs)
- -mail.misar.io, misarmail.com
- -misar.blog and MisarBlog services
- -misar.dev and MisarDev services
- -reach.misar.io, misarreach.com
- -post.misar.io, misarpost.com
Out of scope
- -Denial-of-service (DoS/DDoS) or volumetric attacks
- -Social engineering, phishing, or physical attacks against Misar AI staff or infrastructure
- -Automated scanner output without a demonstrated, reproducible vulnerability
- -Issues in third-party services we use (Stripe, Cloudflare, Supabase) — report those to the vendor
- -Missing security headers or best-practice flags without a demonstrated exploit
- -Use of known-vulnerable library versions without a working proof of concept
Safe Harbor
We will not pursue legal action against, or report to law enforcement, security researchers who in good faith:
- -Follow this policy and make a genuine effort to avoid privacy violations, data destruction, and service disruption.
- -Access only the minimum data necessary to demonstrate a vulnerability, and do not access, modify, or retain other users' data.
- -Report findings promptly and do not exploit them beyond what is needed for a proof of concept.
- -Do not publicly disclose details before remediation or an agreed disclosure date.
Research conducted in accordance with this policy is considered authorized under applicable anti-hacking and anti-circumvention laws, including the Information Technology Act, 2000 (India), the CFAA (US), and analogous laws elsewhere, to the extent we are able to authorize it. If a third party initiates legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized by us.
Related Resources
security.txt
Machine-readable security contact information (RFC 9116).
status.misar.io
Live availability of all Misar services, databases, and infrastructure.
For privacy questions, see our Privacy Policy. For everything else, contact us.