Goafreet
HomePortfolioSupport
Privacy & Data Governance
Version 1.0

Security & Responsible Disclosure Policy

Specifies reasonable organizational security safeguards and defines safe-harbor rules for security researchers.

Effective: 9 September 2026
Last updated: 9 September 2026
Table of Contents (4)
    1. Organizational Security Architecture
    2. Responsible Vulnerability Disclosure Program
    3. Prohibited Testing Activities
    4. Safe Harbor Commitment
Legal Questions?

Need commercial clarification on our terms or standard contracts?

    1. Organizational Security Architecture
    2. Responsible Vulnerability Disclosure Program
    3. Prohibited Testing Activities
    4. Safe Harbor Commitment
Scope & Contractual Summary

Technical security controls, role-based access limits, MFA requirements, and ethical vulnerability disclosure rules.

1
Organizational Security Architecture

Goafreet maintains reasonable administrative, organizational, and technical security safeguards appropriate to the sensitivity of information processed. Controls include end-to-end TLS encryption for data in transit, encrypted storage at rest, strict least-privilege role-based access controls, mandatory multi-factor authentication (MFA) across all administrative tools, endpoint security software, and regular access log reviews.


2
Responsible Vulnerability Disclosure Program

Goafreet welcomes responsible reporting of suspected security vulnerabilities from independent researchers, ethical hackers, and clients. If you discover a potential vulnerability in our web infrastructure or digital tools, please report it privately to info@goafreet.com with detailed technical reproduction steps.


3
Prohibited Testing Activities

In testing for vulnerabilities, researchers must strictly avoid: (a) Denial of Service (DoS/DDoS) attacks or automated brute-force attacks that degrade system performance; (b) Accessing, modifying, or exfiltrating data belonging to any client or third party; (c) Social engineering, phishing, or physical intrusion attempts against Goafreet personnel; and (d) Publicly disclosing an unresolved issue in a manner that creates avoidable harm before Goafreet has been afforded a reasonable window to investigate and deploy remediation.


4
Safe Harbor Commitment

Goafreet will not initiate legal action or invoke cybersecurity criminal statutes against security researchers who discover and report vulnerabilities in good faith and in full compliance with this Responsible Disclosure Policy.

Contractual Hierarchy & Precedence

This document forms part of Goafreet’s operational legal architecture and is intended to be read in conjunction with our Master Service Terms and specific engagement proposals. Where a mutually signed Master Service Agreement (MSA), Statement of Work (SOW), or bilateral Non-Disclosure Agreement (NDA) contains more specific or differing terms, the signed agreement shall strictly prevail for that engagement.


Public Corporate Identification & Contact

Goafreet is an India-based brand management, digital marketing, ecommerce operations, technology engineering, and creative consulting firm operating from Vadodara, Gujarat, India.
Official Communications: info@goafreet.com | Telephone: +91 9106981512

View All 40 Legal PoliciesDocument Version: 1.0 | Updated: 9 September 2026