Responsible Vulnerability Disclosure Policy

Pion Global Private Limited

Effective Date:23 September 2026  | Version:1.0  | Last Updated: 23 September 2026

Our commitment: Pion Global values responsible security research. This policy provides a clear channel for reporting suspected vulnerabilities in Pion Global-owned websites, platforms and the PIEDAP Enterprise Ecosystem, and sets expectations for good-faith research, validation, remediation and coordinated disclosure.

Vulnerability Disclosure at a Glance

Who can report?Security researchers, customers, users, partners and any person who believes they have identified a security vulnerability affecting an in-scope Pion Global asset.
What is covered?Pion Global-owned or controlled public websites, platform interfaces, APIs and related digital services identified in this Policy, subject to the scope and testing rules below.
How do I report?Email [email protected] with the subject "SECURITY VULNERABILITY - [affected asset/platform]". Include enough technical detail for us to reproduce and assess the issue.
Is this a bug bounty?No. This Policy does not create a bug bounty program or any entitlement to payment, reward or compensation.
Can I test safely?Good-faith, non-destructive research that follows this Policy is intended to be treated as authorized by Pion Global for systems under Pion Global's control, subject to the Safe Harbor section below.
When may I disclose publicly?Please coordinate with Pion Global and allow reasonable time for remediation. Our default coordination target is up to 90 calendar days after validation unless a different timeline is agreed or circumstances require faster action.

1. Purpose and Principles

Pion Global Private Limited ("Pion Global", "we", "our" or "us") is committed to protecting the confidentiality, integrity and availability of its digital services. We recognize that independent security research can help identify weaknesses before they cause harm. This Policy is designed to make vulnerability reporting clear, safe and constructive. It explains what systems are in scope, what types of testing are permitted, how to submit a report, how we handle reports, and how coordinated disclosure should work.

This Policy is not a licence to access data that does not belong to you, disrupt services, bypass legal restrictions, or test third-party systems that Pion Global does not own or control.

2. Scope: Pion Global Digital Properties

This Policy applies to Pion Global-owned or controlled public digital properties and services listed below, including associated public-facing interfaces and APIs where Pion Global controls the affected system. A platform-specific security policy or contract may define a narrower or more specific scope and will take precedence for that environment.

PropertyClassificationPrimary public scope
Pion Global Corporate websiteCorporate websitewww.pionglobal.com
GRCNestPion Global platformwww.grcnest.ai
NexGenQEPion Global platformwww.nexgenqe.com
TalenaisePion Global platformPion Global-owned Talenaise digital properties and interfaces, where made publicly available
Consent Management PlatformPion Global platformwww.dpdpaconsent.in
PIEDAPPion Global Enterprise Ecosystemwww.piedap.io and Pion Global-controlled ecosystem interfaces

Scope clarification: Only systems that Pion Global owns or controls are authorized by this Policy. Third-party hosting providers, cloud services, identity providers, payment providers, customer environments and other external services are not automatically in scope, even when they are integrated with a Pion Global platform.

3. Authorization and Safe Harbor for Good-Faith Research

If you conduct security research in good faith, stay within the scope of this Policy and comply with the testing requirements below, Pion Global intends to treat that research as authorized with respect to Pion Global-controlled systems and will not initiate legal action solely because of that compliant research.

If a third party initiates legal action against you for research that Pion Global determines was conducted in compliance with this Policy, we may, where appropriate and legally permissible, confirm that the activity was conducted under this Policy.

This Safe Harbor applies only to Pion Global-controlled systems and only to activity consistent with this Policy. Pion Global cannot authorize activity on third-party systems, waive the rights of third parties, or provide immunity from laws or obligations that are outside Pion Global's control.

Safe Harbor does not apply to extortion, threats, demands for payment as a condition of non-disclosure, intentional data theft, destructive activity, persistence, service disruption, or activity intended to cause harm.

4. How to Report a Vulnerability

Send vulnerability reports to: [email protected]  |  Subject: SECURITY VULNERABILITY - [affected asset/platform]

Please provide enough information for us to reproduce and assess the issue. A useful report should include:

• Affected website, platform, endpoint, API, URL or other asset.
• A clear description of the vulnerability and the security impact you believe it creates.
• Step-by-step reproduction instructions and the minimum proof of concept necessary to demonstrate the issue.
• Any relevant request/response samples, screenshots, logs or test-account information, with sensitive data removed wherever possible.
• Known prerequisites, affected roles or permissions, and whether the issue appears to affect more than one tenant or user.
• Vulnerability category (for example CWE) and severity assessment (for example CVSS), if known.
• Your preferred name or attribution, whether you wish to remain anonymous, and any coordinated-disclosure expectations.

Urgent reports: If you believe a vulnerability is being actively exploited, exposes customer data, enables cross-tenant access, or creates an immediate risk to service integrity, mark the email subject "URGENT SECURITY VULNERABILITY".

5. Research and Testing Guidelines

To remain within this Policy, please follow these rules while testing:

Use your own accounts and data. Do not access another person's or customer's account, records or tenant except where strictly necessary to confirm an issue and only to the minimum extent required.
Use the minimum testing necessary. Demonstrate the vulnerability without escalating access, extracting data, establishing persistence or exploring unrelated systems.
Protect privacy and confidentiality. If you encounter personal data, credentials, secrets, confidential business information or customer data, stop further access and report the issue immediately.
Avoid disruption. Keep request rates reasonable and do not impair availability, performance, monitoring, backups, business operations or other users.
Do not alter production data. Do not create, modify, delete, encrypt, corrupt or destroy data except data in your own authorized test account where necessary and safe.
Do not retain access. Do not install malware, web shells, backdoors, scheduled tasks, new privileged accounts or other persistence mechanisms.
Respect boundaries. Do not pivot from an in-scope system to customer, employee or third-party systems and do not use discovered credentials to access unrelated services.
Use automation responsibly. Low-impact automated tools may be used only where they do not create excessive traffic or disruption. Scanner output alone may not be sufficient to demonstrate a valid vulnerability.

6. Prohibited Testing and Normally Out-of-Scope Findings

6.1 Prohibited Testing Methods

• Denial-of-service (DoS/DDoS), stress testing, traffic flooding or any activity intended to degrade availability.
• Social engineering, phishing, smishing, vishing, pretexting, impersonation or targeting Pion Global employees, customers, contractors or partners.
• Physical intrusion, tailgating, device theft, facility testing or attempts to access offices, data centres or restricted areas.
• Credential stuffing, large-scale password spraying, brute force attacks or acquisition/use of credentials from unlawful sources.
• Malware deployment, ransomware, destructive payloads, persistence mechanisms or deliberate exploitation beyond what is necessary to prove the vulnerability.
• Data exfiltration, mass downloading, bulk enumeration, or copying customer, employee or confidential information.
• Testing third-party systems, customer-managed environments or external providers without separate authorization from the relevant owner.

6.2 Findings Normally Considered Out of Scope

The following are normally treated as informational unless you can demonstrate a realistic, material security impact:

• Missing security headers, cookie attributes or configuration hardening recommendations without an exploitable impact.
• Clickjacking on pages that perform no sensitive action, self-XSS, or issues requiring a user to attack themselves.
• Rate-limiting observations, user/account enumeration or brute-force concerns without a practical security consequence.
• Outdated software/library reports based only on version detection, without evidence that an exploitable vulnerability affects the Pion Global deployment.
• TLS/SSL configuration observations that do not create a meaningful confidentiality or integrity risk.
• Scanner-only findings, theoretical weaknesses or best-practice deviations without reproducible impact.
• Vulnerabilities entirely within a third-party product or service where no Pion Global-specific exposure or misconfiguration is demonstrated.
• AI model quality issues such as ordinary hallucinations, subjective output quality, bias concerns or prompt-injection demonstrations that do not result in unauthorized data access, security-control bypass, privileged action, secret exposure or comparable security impact.

7. AI, Agentic and Automation-Related Security Findings

Pion Global platforms may include AI-assisted, automated or agentic capabilities. We welcome reports of AI-related security weaknesses when they demonstrate a concrete effect on confidentiality, integrity, authorization, tenant isolation or system safety. Examples may include:

• Prompt or instruction injection that causes unauthorized access to data, tools, actions or privileged functions.
• Cross-tenant or cross-user information leakage caused by AI retrieval, memory, context handling or orchestration.
• Exposure of credentials, API keys, secrets or protected configuration through AI or agent workflows.
• Unauthorized execution of actions by an AI agent, connector or automation workflow.
• Bypass of access control, approval, policy or security boundaries through model/tool interaction.

Model-output disagreements, expected probabilistic behaviour, general jailbreak prompts or prompt disclosure without a demonstrated security consequence may be treated as product-quality feedback rather than a security vulnerability.

8. Handling Sensitive Data Discovered During Research

If you unexpectedly encounter personal data, customer data, credentials, secrets, confidential business information or any data that is not yours:

• Stop accessing or testing the affected data path as soon as you have enough evidence to report the issue.
• Do not copy, download, store, transmit, publish or share the data beyond the minimum information necessary for Pion Global to understand the risk.
• Do not contact affected customers, employees or individuals directly unless Pion Global asks you to do so or law requires it.
• Protect any information inadvertently collected and securely delete it when Pion Global confirms it is no longer needed, subject to applicable law.
• Redact personal data, credentials and confidential information from screenshots, logs, proof-of-concept material and public communications.

9. What You Can Expect From Pion Global

For reports submitted in good faith with sufficient technical detail, Pion Global aims to:

StagePion Global target
AcknowledgementAcknowledge receipt within 3 business days where reasonably practicable.
Initial triagePerform an initial review and provide a status or request for further information within 7 business days where reasonably practicable.
ValidationAttempt to reproduce the issue, determine scope and impact, and prioritize it using a risk-based approach. Pion Global may use CVSS or an equivalent internal severity methodology.
RemediationWork toward an appropriate fix, mitigation or risk-treatment plan based on severity, exploitability, customer impact, architectural complexity and third-party dependencies.
CommunicationProvide reasonable status updates for validated material vulnerabilities, particularly high- and critical-severity issues, while remediation is active.
ClosureInform the reporter when the issue has been resolved, mitigated, accepted as risk, determined to be a duplicate, or found not to be a security vulnerability, where appropriate.

These are service targets, not guaranteed resolution deadlines. Some issues require additional investigation, coordinated vendor fixes, architectural changes or customer deployment actions.

10. Coordinated Disclosure

We ask researchers to give Pion Global a reasonable opportunity to investigate and remediate a validated vulnerability before public disclosure. As a default coordination target, please allow up to 90 calendar days after Pion Global validates the issue, unless a different timeline is mutually agreed.

The appropriate disclosure timeline may be shorter or longer depending on active exploitation, severity, availability of mitigations, third-party dependencies, customer impact and public safety. We will work in good faith with the reporter on an appropriate disclosure plan.

Where a vulnerability affects multiple vendors, widely used components or the broader ecosystem, Pion Global may coordinate with CERT-In, an appropriate CSIRT/CERT, a CVE Numbering Authority (CNA), the affected vendor or other relevant security coordination body. Technical information may be shared to the extent reasonably necessary for validation and remediation.

Please do not publish exploit code, customer data, personal data, credentials, secrets or information that would materially increase the risk of exploitation before adequate mitigations are available.

11. Third-Party Services and Dependencies

Pion Global platforms and the PIEDAP Enterprise Ecosystem may integrate with cloud providers, identity services, open-source components, enterprise applications, customer systems and other third-party technologies. This Policy does not grant permission to test systems that are owned or controlled by those third parties.

If you discover a vulnerability that appears to originate in a third-party component but affects a Pion Global deployment, please report the Pion Global impact to us. We may coordinate with the relevant vendor or security response team. Where appropriate, we may ask you to coordinate directly with that third party under its own vulnerability disclosure policy.

12. Recognition, Rewards and Duplicate Reports

This is a vulnerability disclosure program, not a bug bounty program. Submission of a report does not create any right to financial payment, reward, employment, contract or other compensation.

At Pion Global's discretion, and with the reporter's consent, we may acknowledge individuals who make useful good-faith reports. If multiple people report the same issue, Pion Global may treat later submissions as duplicates.

13. Reporter Information and Confidentiality

Pion Global will use information provided in a vulnerability report to investigate, reproduce, remediate and document the reported issue, communicate with the reporter, meet security or legal obligations, and coordinate with affected vendors or security-response organizations where necessary.

We will limit disclosure of reporter contact information to those who reasonably need it for vulnerability handling, legal compliance or coordination. If you prefer to remain anonymous, you may submit a report without identifying yourself, although this may limit our ability to follow up.

Pion Global's Privacy Policy applies to personal data we process about reporters.

14. No Warranty and No Transfer of Rights

This Policy is intended to facilitate responsible vulnerability reporting. It does not provide a warranty regarding the security or availability of any Pion Global system and does not transfer intellectual property rights, grant access rights beyond the limited authorization described above, or modify any signed customer, partner, employment or other agreement.

15. Changes to This Policy

Pion Global may update this Policy as its websites, platforms, Enterprise Ecosystem, security processes, laws or industry practices evolve. The "Last Updated" date at the top of the document indicates the latest published revision. Material changes will be reflected in the published version of this Policy.

16. Contact

OrganisationPion Global Private Limited
Security reporting email[email protected]
Email subjectSECURITY VULNERABILITY - [affected asset/platform]
Corporate websitewww.pionglobal.com
Business address48, 4th B Main, Classic Paradise Layout, Begur Road, Bengaluru, Karnataka, India

17. Reference Frameworks (Informative)

This Policy is informed by recognized vulnerability disclosure and coordination practices. Reference to these frameworks does not represent certification or a claim of formal conformity.

  • NIST SP 800-216, Recommendations for Federal Vulnerability Disclosure Guidelines.
  • ISO/IEC 29147, Vulnerability disclosure, and ISO/IEC 30111, Vulnerability handling processes.
  • CERT-In Responsible Vulnerability Disclosure and Coordination Policy (India).
  • RFC 9116, security.txt, for publishing machine-readable vulnerability-reporting contact information.