This Privacy Policy is effective as of 1st October, 2022.
System security is a top priority at Paynims. Regardless of the amount of effort any
Company puts into its system security, ensuring a safe and secure environment is a
continuous process. Paynims believes that working with skilled security researchers across
the globe is crucial in identifying any weaknesses in its systems, and in ensuring that its
security is maintained.
Paynims hence invites all skilled security researchers to participate in its Vulnerability
Disclosure Program (the ‘Program’)
Paynims will engage with you as an external security researcher (the Researcher) when
vulnerabilities are reported to us in compliance with the below Responsible Disclosure
Policy.
If a Researcher follows the rules set out in this Responsible Disclosure Policy when
reporting a security vulnerability to us, unless prescribed otherwise by law or the payment
scheme rules, we commit to:
As part of providing services to its customers, Paynims uses integrations with various third-party software. This Program does not extend to any such third-party software and bugs or vulnerabilities detected in such third-party software will not be considered as a valid find. Notwithstanding the above, any such vulnerabilities communicated to Paynims may further be transmitted/informed to the third-party service provider.
These terms govern the terms of your access and participation in the Paynims Vulnerability Disclosure Program and you deem to agree and undertake to abide by these terms while participating in the Program and submitting your reports. By agreeing to participate in the Program, you agree to abide by the terms hereunder.
1. Drop us an email at abhishek@paynims.com (SUBJECT: SUSPECTED VULNERABILITY ON Paynims) with the details of the vulnerability identified to register yourself.
2. Once registered, you shall only use the registered email Id to interact with Paynims security team. Do not use personal emails, social media accounts, or other private connections to contact a member of the security team in regard to vulnerabilities or any program-related issues, unless you have been instructed to do so.
3. Upon detection of a vulnerability/bug, you shall immediately report it to the Paynims team and such bug/vulnerability report shall include:
However, Paynims reserves the right to refuse your request if any of the above-mentioned details are not provided by you to Paynims.
While researching, you shall strictly refrain from indulging in:
Paynims reserves its right to expand this list and include additional exclusions when required.
1. You must abide by the law and intimation of vulnerability shall be as per the law.
2. Paynims reserves the right to discontinue the Program with prior intimation to registered researchers.
3. By submitting information about a potential vulnerability, you are agreeing to these terms and conditions and granting Paynims a worldwide, royalty-free, non-exclusive license to use your submission for the purpose of addressing vulnerabilities.
4. Paynims reserves the right to hold you responsible and liable for any consequences arising out of your breach of these terms or breach of confidentiality.. You hereby undertake to indemnify and keep indemnified Paynims and its directors, officers, employees and consultants against all losses, damages, claims or liabilities that they incur due to any Fraud, Willful Misconduct, Gross Negligence, breach of confidentiality or due to breach of personal confidential information.
By default, this program is in “PUBLIC NON-DISCLOSURE” mode which means:
"This program does not allow public disclosure. One should not release the information about vulnerabilities found in this program to public, failing which shall be liable for legal penalties!”
We will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy. We consider activities conducted consistent with this policy to constitute “authorized” conduct under the Computer Fraud and Abuse Act. We will not bring a DMCA claim against you for circumventing the technological measures we have used to protect the applications in scope. If legal action is initiated by a third party against you and you have complied with Paynims’s will take steps to make it known that your actions were conducted in compliance with this policy.
These terms shall be governed by the Laws of India and the courts at Lucknow, India shall have exclusive jurisdiction to try any disputes that may arise out of this Program.
Last Updated on 1st October 2022 at 11:00 AM