Security & Responsible Disclosure
Effective 10 October 2026. Operator: Support IT Ventures, Mumbai, Maharashtra, India.
Kavach promises others secure results, so it has to hold itself to the same standard. This page describes how we secure the platform and how to report a weakness in it.
1. How we secure Kavach
- The scanner only makes read-only requests, pins every outbound connection to a validated public address (defence against SSRF and DNS rebinding), never follows redirects blindly, and refuses internal, private and cloud-metadata destinations. Every refusal is logged as a security event.
- Exposure checks never retain the contents of discovered secrets; findings carry only a classification, size and hash. Evidence manifests are cryptographically signed and verifiable.
- All traffic is encrypted (TLS 1.2+, HSTS); every response carries a strict Content Security Policy and the other headers Kavach grades others on. Kavach’s own domain is scanned by Kavach, and an automated self-audit test runs before every release.
- API keys are stored hashed; payments are handled entirely by our payment provider; servers are firewalled, patched automatically, accessed by key only, and backed up daily.
2. Reporting a vulnerability
If you believe you have found a security issue in Kavach (https://kavachscan.com, its API, CLI or
GitHub Action), please email abuse@kavachscan.com
with enough detail to reproduce it. Our machine-readable contact is published at
/.well-known/security.txt. We acknowledge reports within 3 business days, keep you
informed, and credit researchers who wish to be named once a fix is released.
3. Safe harbour
We will not pursue legal action against researchers who act in good faith: test only systems we operate, avoid privacy violations, data destruction and service degradation, do not access or retain other users’ data beyond what is needed to demonstrate the issue, and give us reasonable time to fix the issue before any public disclosure. Scanning third-party websites is outside this safe harbour — see the Acceptable Use Policy.
4. Out of scope
Denial-of-service testing, social engineering of our staff or providers, physical attacks, and findings in third-party services we rely on (report those to the respective vendor).
5. Rewards
We do not currently run a paid bug bounty. We do offer public acknowledgement and free Kavach plans to researchers whose reports lead to a fix.