Service Lee Technologies Private Limited (“Servify”) takes the security of its systems and data very seriously and continuously strives to maintain the security and integrity of its products and services through state-of-art processes, security frameworks and regular audits. Servify is committed to working with the security researcher community to improve the same. We strongly believe that a close partnership with security researchers on the latest trends to understand security threats and vulnerability identification creates a powerful ecosystem of security, making customers secure and confident to use the products and services along with all the impactful features. Servify, therefore, has adopted this Vulnerability Disclosure Program (“VDP”) to engage security researchers to report any security vulnerability that affects any product or service of Servify in a responsible manner. VDP is an initiative driven and managed by Servify’s Information Security team.
If you are a security researcher and have discovered any security vulnerability in the applications identified below, please report it to us as per our VDP. Reports that fall within the scope of VDP are also eligible for a certificate of thanks and recognition on our Security Hall of Fame as shared below.
You may report a vulnerability using the “Submit Report” button on this page.
If you consider yourself to be eligible to participate in the VDP, you must meet the following criteria:
You are not eligible to participate in the VDP if you meet any of the following criteria:
You are responsible for reviewing and complying with your employer’s rules for participating (including to the extent applicable receiving the recognition in the Security Hall of Fame) in this VDP. It is your responsibility to comply with any polices that your employer may have that would affect your eligibility to participate in our VDP or to receive the recognition. If you are participating in violation of your employer’s policies, you may be disqualified from participating or receiving any recognition in our Security Hall of Fame.
Further, Servify employees and contractors, as well as their immediate family members are strictly prohibited from participating in the VDP or sharing information with an external security researcher to bypass this prohibition (in which case all parties are ineligible under this VDP).
Please note that failure to comply with any of the above-mentioned criteria would immediately disqualify you from being eligible for an award under the VDP. Further, any conduct by a security researcher that appears to be unlawful, malicious, or of criminal in nature, including but not limited to, extortion would be immediately disqualified under this VDP.
There may be additional restrictions on your eligibility to participate in the VDP if the same is deemed necessary by the Management of Servify. If at any point while researching a vulnerability, you are unsure whether you should continue, please send an email to infosec@servify.fistbumpdigital.com without any delay.
In Scope
The following Servify owned websites and mobile applications are in scope of VDP:
Out of Scope
Servify owned WordPress websites and Sandbox (dev, staging or UAT) portals that are not within the scope of VDP, include, but are not limited to:
If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We may in our sole discretion modify or amend the scope of this VDP from time to time.
Exclusions
When reporting vulnerabilities, please consider the attack scenario/exploitability and security impact of the bug. The following issues are considered out of scope of this VDP, and we will not accept any of the following types of attacks:
Guidelines for Testing
Reporting Process
If you have identified a potential security vulnerability issue, please follow the terms and conditions of VDP before submitting a report on such security vulnerability. By submitting the Report, you are deemed to have agreed to terms and conditions of the VDP.
Any query or accompanying material after the report is submitted, can be sent to infosec@servify.com. All the shared documents must be password protected. Password must be sent on separate email. The security vulnerability identified by you must be deemed original (i.e. not previously reported to Servify, and also not publicly disclosed), in order for you to receive recognition for the same.
Once a Report is submitted, Servify reserves the right to request from you, and you already accept to abide by this request, to securely and irreversibly delete any data related to such Report, including, without limitation, any data about Servify and its services, affiliates or any of its users, employees, or agents. Additionally, you agree to securely and irreversibly delete any data related to the Report immediately upon it no longer being reasonably necessary to retain for the purposes of conveying the impact or scope of the reported issue, after verifying with Servify that it is no longer necessary, and/or if the Report is closed, regardless of the outcome.
Review and Response Protocol
After a Report is submitted in accordance with this VDP, Servify will review the Report and validate its eligibility. Servify will make reasonable efforts to respond to participants of the VDP. The timelines for response are below:
The aforesaid timelines are indicative and may vary depending on the complexity and completeness of your Report, as well as on the number of Reports we receive.
Servify retains sole discretion in determining which Reports are qualified. If Servify receives multiple Reports for the same issue/vulnerabilities from different parties, the participant who submitted the first eligible Report will be qualified for the Security Hall of Fame in terms of this VDP. The decision made by Servify’s security team regarding validity, severity & impact of a vulnerability will be considered final and cannot be contested. Servify may share your vulnerability reports with any affected partners, vendors or open-source projects.
Recognition – Security Hall of Fame
Servify greatly appreciates anyone who has contributed to the security of our users via responsible disclosure of vulnerabilities to us in accordance with this VDP. We thank you for your efforts.
We currently do not offer any bounty/cash reward or any compensation in kind. However, for genuine ethical disclosures in accordance with this VDP, we will gladly acknowledge your contribution publicly in our Security Hall of Fame if you want a public acknowledgement.
Eligibility for Security Hall of Fame:
Authorization/Safe Harbor
Any activities conducted in a manner consistent with this VDP will be considered authorized conduct and we will not initiate any legal action against you. This limited authorization does not provide you with authorization to access Company data or another person’s account.
Servify cannot authorize any activity on third-party products or guarantee they won’t pursue legal action against you. Servify will not be responsible for your liability from actions performed on third parties. However, if legal action is initiated by any third party against you in connection with activities conducted under this VDP, we will take steps to make it known that your actions were conducted in compliance with this VDP.
We waive any restrictions in our applicable Terms of Service that would prohibit your participation in this VDP in accordance with the terms of, for the limited purpose of your security research under this VDP.
Privacy
Please see Servify’s Privacy Policy for disclosures relating to the collection, store and use of your personal information (such as name, email address, phone number, public profile) in connection with the VDP. Notwithstanding the Privacy Policy, your information may be shared with service providers of Servify in relation to the VDP. Your consent is deemed to be granted for such disclosures when you make a Report.
Confidentiality
Any information you receive, collect or otherwise obtain about Servify and its services, affiliates or any of its users, employees, or agents in connection with VDP (whether after or before you joined the VDP, notably as a result of you finding and/or investigating a security bug in our in-scope applications or infrastructure) must be kept confidential, held in trust and strictest confidence, only used in connection with the VDP, and should not be disclosed to any third party. You must protect it against disclosure to any person in the same manner and with the same degree of care, but not less than a reasonable degree of care, which you would do to protect your own confidential information.
You will not:
All Confidential Information furnished to you by Servify will remain the exclusive property of Servify and Servify will have the sole and exclusive ownership of all right, title, and interest in and to the confidential information, including ownership of all copyrights, patents and trade secrets pertaining thereto, subject only to the rights and privileges expressly granted by Servify under the terms of this VDP.
Promptly upon Servify’s request at any time, you will return / cause to be returned to Servify all the confidential information, including all materials or documents, any copies, summaries and notes of the contents thereof (whether in hard or soft copy form) without limitation, all copies of any analyses, compilations, studies or other documents prepared by and/or for company, containing or reflecting any confidential information and give written certification accordingly.
You understand and acknowledge that any misappropriation or disclosure of any of the confidential information in violation of the confidentiality obligations will cause Servify grave and irreparable harm, loss and injury, the amount of which may be difficult to ascertain. You agree that Servify has the right to apply to a court of competent jurisdiction for specific performance and/or an order restraining and enjoining any such further disclosure or breach and for such other relief as Servify will deem appropriate, without posting or the need to post any bond or other security. Such right of Servify to obtain equitable relief in the form of specific performance, temporary restraining order, temporary or permanent injunction or any other equitable remedy which may then be available to it, without the necessity of proving actual damages, will be in addition to the remedies otherwise available to it at law. You expressly waive the defense that a remedy in damages will be adequate.
Grant Of License
Servify does not claim any ownership rights to your Report. However, by providing any Report to Servify, you grant Servify and its subsidiaries/affiliates the following non-exclusive, irrevocable, perpetual, royalty free, worldwide, sub-licensable license to the intellectual property in your Report:
You are deemed to have understood and acknowledged that Servify may have developed or commissioned materials similar or identical to your Report, and you waive any claims you may have resulting from any similarities to your Report.
Remedies
You will indemnify, defend and hold harmless Servify and its affiliates and their respective directors, employees and consultants (“Indemnified Parties”) from and against any losses, costs, expenses, damages of whatsoever nature which may be incurred or suffered by any Indemnified Party arising out of or as a result of any breach of VDP (including negligence) or otherwise of any of your obligations contained herein.
You also expressly agree and acknowledge that a breach of your obligations under this VDP will result in irreparable and continuing injury to Servify, which may not be fully compensated and for which it would have no adequate remedies under this VDP or under law and for which monetary damages alone would not constitute reasonable recompense. Notwithstanding anything to the contrary contained in this VDP, the indemnification rights of Servify are in addition and without prejudice to any remedies that Servify may have under applicable law or equity, including specific performance and injunctive relief. Every right or remedy granted by this VDP, whether provided herein or conferred by any statute, common law, custom, trade or usage, is cumulative and not alternative and may be enforced successively or concurrently. Further, appropriate legal recourse will be taken if the identified vulnerabilities are exploited for unlawful gains or getting access to restricted customer or system information or impairing Servify’s systems or program guidelines are not followed or breach of the confidential information, and you will not be eligible for VDP.
General
Nothing contained in this VDP will be construed to obligate Servify to disclose any information to you.
This VDP will be fully binding upon you.
The failure of Servify to insist upon or enforce strict performance of any of the provisions of this VDP or to exercise any rights or remedies under this VDP will not be construed as a waiver or relinquishment to any extent of Servify’s rights to assert or rely upon any such provisions, rights or remedies in that or any other instance; rather the same will remain in full force and effect.
This VDP may be changed, amended, varied, modified or cancelled by Servify at any time, without notice. In case of any change, amendment or modification, a revised version of VDP will be posted here.
This VDP does not intend, in any manner, to create any joint venture, partnership or any other relation (unless expressly agreed in writing) with you and Servify.
This VDP will be governed by, construed and enforced in accordance with the laws of the Republic of India.
The courts in Mumbai, India will have the exclusive jurisdiction.
Servify’s vision is to be the platform that brings together all eco-system partners to deliver consumer happiness through great after-sales service.
Copyright © 2024 Servify. All Rights Reserved