Skip to content
Misar.io
Vulnerability Disclosure Policy

Security at Misar AI

We value the work of security researchers. If you believe you have found a vulnerability in any Misar AI product or service, we want to hear from you — and we commit to working with you in good faith.

Last updated: July 5, 2026

How to Report a Vulnerability

Email your report to our security team. Encrypt sensitive details where possible and include everything we need to reproduce the issue.

Report by email

legal@misar.io — the same contact published in our security.txt.

A good report includes

  • -The affected product, domain, or API endpoint and the type of vulnerability (e.g. XSS, IDOR, SSRF, auth bypass).
  • -Step-by-step reproduction instructions, including any request/response samples or proof-of-concept code.
  • -The impact you believe the issue has, and any suggested remediation.
  • -How you would like to be credited (or that you prefer to remain anonymous).

What to Expect From Us

We take every report seriously and commit to the following response targets:

Acknowledgement

We will acknowledge receipt of your report within 72 hours.

Triage & Assessment

We will assess severity and confirm or decline the finding within 7 business days.

Remediation Updates

We will keep you informed of progress until the issue is resolved.

We ask that you give us a reasonable opportunity to remediate a confirmed vulnerability before any public disclosure. We will coordinate a disclosure timeline with you — typically within 90 days of triage.

Scope

This policy covers all production services operated by Misar AI Technology Private Limited.

In scope

  • -misar.io, www.misar.io, id.misar.io, tools.misar.io, docs.misar.io
  • -api.misar.io (all product API slugs)
  • -mail.misar.io, misarmail.com
  • -misar.blog and MisarBlog services
  • -misar.dev and MisarDev services
  • -reach.misar.io, misarreach.com
  • -post.misar.io, misarpost.com

Out of scope

  • -Denial-of-service (DoS/DDoS) or volumetric attacks
  • -Social engineering, phishing, or physical attacks against Misar AI staff or infrastructure
  • -Automated scanner output without a demonstrated, reproducible vulnerability
  • -Issues in third-party services we use (Stripe, Cloudflare, Supabase) — report those to the vendor
  • -Missing security headers or best-practice flags without a demonstrated exploit
  • -Use of known-vulnerable library versions without a working proof of concept

Safe Harbor

We will not pursue legal action against, or report to law enforcement, security researchers who in good faith:

  • -Follow this policy and make a genuine effort to avoid privacy violations, data destruction, and service disruption.
  • -Access only the minimum data necessary to demonstrate a vulnerability, and do not access, modify, or retain other users' data.
  • -Report findings promptly and do not exploit them beyond what is needed for a proof of concept.
  • -Do not publicly disclose details before remediation or an agreed disclosure date.

Research conducted in accordance with this policy is considered authorized under applicable anti-hacking and anti-circumvention laws, including the Information Technology Act, 2000 (India), the CFAA (US), and analogous laws elsewhere, to the extent we are able to authorize it. If a third party initiates legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized by us.