Security & Responsible Disclosure Policy
Specifies reasonable organizational security safeguards and defines safe-harbor rules for security researchers.
Table of Contents (4)
Legal Questions?
Need commercial clarification on our terms or standard contracts?
Table of Contents (4 Sections)
Scope & Contractual Summary
Technical security controls, role-based access limits, MFA requirements, and ethical vulnerability disclosure rules.
Organizational Security Architecture
Goafreet maintains reasonable administrative, organizational, and technical security safeguards appropriate to the sensitivity of information processed. Controls include end-to-end TLS encryption for data in transit, encrypted storage at rest, strict least-privilege role-based access controls, mandatory multi-factor authentication (MFA) across all administrative tools, endpoint security software, and regular access log reviews.
Responsible Vulnerability Disclosure Program
Goafreet welcomes responsible reporting of suspected security vulnerabilities from independent researchers, ethical hackers, and clients. If you discover a potential vulnerability in our web infrastructure or digital tools, please report it privately to info@goafreet.com with detailed technical reproduction steps.
Prohibited Testing Activities
In testing for vulnerabilities, researchers must strictly avoid: (a) Denial of Service (DoS/DDoS) attacks or automated brute-force attacks that degrade system performance; (b) Accessing, modifying, or exfiltrating data belonging to any client or third party; (c) Social engineering, phishing, or physical intrusion attempts against Goafreet personnel; and (d) Publicly disclosing an unresolved issue in a manner that creates avoidable harm before Goafreet has been afforded a reasonable window to investigate and deploy remediation.
Safe Harbor Commitment
Goafreet will not initiate legal action or invoke cybersecurity criminal statutes against security researchers who discover and report vulnerabilities in good faith and in full compliance with this Responsible Disclosure Policy.
Contractual Hierarchy & Precedence
This document forms part of Goafreet’s operational legal architecture and is intended to be read in conjunction with our Master Service Terms and specific engagement proposals. Where a mutually signed Master Service Agreement (MSA), Statement of Work (SOW), or bilateral Non-Disclosure Agreement (NDA) contains more specific or differing terms, the signed agreement shall strictly prevail for that engagement.
Public Corporate Identification & Contact
Goafreet is an India-based brand management, digital marketing, ecommerce operations, technology engineering, and creative consulting firm operating from Vadodara, Gujarat, India.
Official Communications: info@goafreet.com | Telephone: +91 9106981512
