Kavach

Security & Responsible Disclosure

Effective 10 October 2026. Operator: Support IT Ventures, Mumbai, Maharashtra, India.

Kavach promises others secure results, so it has to hold itself to the same standard. This page describes how we secure the platform and how to report a weakness in it.

1. How we secure Kavach

2. Reporting a vulnerability

If you believe you have found a security issue in Kavach (https://kavachscan.com, its API, CLI or GitHub Action), please email abuse@kavachscan.com with enough detail to reproduce it. Our machine-readable contact is published at /.well-known/security.txt. We acknowledge reports within 3 business days, keep you informed, and credit researchers who wish to be named once a fix is released.

3. Safe harbour

We will not pursue legal action against researchers who act in good faith: test only systems we operate, avoid privacy violations, data destruction and service degradation, do not access or retain other users’ data beyond what is needed to demonstrate the issue, and give us reasonable time to fix the issue before any public disclosure. Scanning third-party websites is outside this safe harbour — see the Acceptable Use Policy.

4. Out of scope

Denial-of-service testing, social engineering of our staff or providers, physical attacks, and findings in third-party services we rely on (report those to the respective vendor).

5. Rewards

We do not currently run a paid bug bounty. We do offer public acknowledgement and free Kavach plans to researchers whose reports lead to a fix.