Responsible Disclosure Policy
At Indian Institute of Neuro Mind (IINM), we take the security and privacy of our students, users, website and digital services seriously.
If you believe you have discovered a security vulnerability in an IINM website, application, platform or online service, we encourage you to report it responsibly so that our team can investigate and address the issue.
We appreciate the efforts of security researchers and responsible individuals who help us improve the security of our systems.
What You Can Report
You may report security vulnerabilities that could affect the confidentiality, integrity or availability of IINM systems or user information.
Examples may include:
-
Authentication or login vulnerabilities.
-
Unauthorised access to accounts or data.
-
Access-control vulnerabilities.
-
Sensitive information exposure.
-
Cross-Site Scripting (XSS).
-
SQL Injection or other injection vulnerabilities.
-
Server-side request vulnerabilities.
-
Security misconfiguration.
-
Insecure direct object references.
-
Privilege escalation.
-
Session-management vulnerabilities.
-
Payment-related security vulnerabilities.
-
API security vulnerabilities.
-
Other vulnerabilities that could reasonably create a security risk.
This list is not exhaustive. If you believe an issue may have a meaningful security impact, we encourage you to report it.
How to Report a Vulnerability
Please report suspected vulnerabilities privately through the official IINM security contact channel.
Security Contact
Indian Institute of Neuro Mind (IINM)
Phone:
+91 82829 56765
Website:
https://iinmedu.com
Please do not publicly disclose a vulnerability before IINM has had a reasonable opportunity to investigate and address it.
Information to Include in Your Report
To help us investigate your report efficiently, please provide as much of the following information as reasonably possible:
-
A clear description of the vulnerability.
-
The affected website, application, API or service.
-
The affected URL or endpoint, where applicable.
-
Steps required to reproduce the issue.
-
Proof-of-concept, if available.
-
Screenshots, logs or other supporting information.
-
The potential security impact.
-
Any relevant technical details.
-
Your preferred method of contact.
Please avoid including unnecessary personal or sensitive information in your report.
Responsible Testing Guidelines
When investigating a potential vulnerability, please follow these principles:
-
Test only systems and services owned or operated by IINM.
-
Do not access, modify, delete or disclose another person's data.
-
Do not intentionally disrupt or degrade our services.
-
Do not perform denial-of-service or resource-exhaustion testing.
-
Do not use social engineering, phishing or impersonation against IINM employees, students or users.
-
Do not install malware or persistent access mechanisms.
-
Do not alter, delete or destroy data.
-
Do not attempt to gain access to systems beyond what is reasonably necessary to demonstrate the vulnerability.
-
Stop testing if you encounter sensitive user information that is not necessary to demonstrate the vulnerability.
-
Do not publicly disclose the vulnerability before coordinating with IINM.
If you accidentally access information belonging to another user, stop testing and report the issue immediately. Do not copy, download, modify or share the information.
Out-of-Scope Activities
The following activities are generally not considered acceptable security testing:
-
Denial-of-service or distributed denial-of-service attacks.
-
Spam or bulk messaging.
-
Social engineering or phishing.
-
Credential theft or credential stuffing.
-
Brute-force attacks against user accounts.
-
Automated high-volume scanning that may affect service availability.
-
Physical attacks against IINM facilities or equipment.
-
Attacks against third-party services that are not controlled by IINM.
-
Testing involving intentional destruction or modification of data.
-
Accessing or retaining personal information that is not necessary to demonstrate the vulnerability.
-
Any activity that violates applicable law.
If you are uncertain whether a particular testing method is acceptable, please contact IINM before conducting the test.
What Happens After You Report
After receiving a vulnerability report, IINM may:
-
Acknowledge receipt of the report.
-
Review and validate the reported issue.
-
Assess the potential impact and severity.
-
Investigate the affected system or service.
-
Take appropriate corrective or mitigation measures.
-
Communicate with the reporter where additional information is required.
Response and remediation timelines may vary depending on the complexity and severity of the vulnerability.
Vulnerability Severity
IINM may assess reported vulnerabilities based on factors such as:
-
Potential impact on users.
-
Confidentiality impact.
-
Integrity impact.
-
Availability impact.
-
Exploitability.
-
Number of potentially affected users.
-
Complexity of exploitation.
-
Whether authentication or user interaction is required.
The final severity classification may be determined by IINM based on the circumstances of the particular issue.
Good-Faith Security Research
IINM appreciates good-faith security research intended to identify and responsibly disclose vulnerabilities.
Where a security researcher follows this policy, acts in good faith, avoids unnecessary access or damage, and provides IINM with a reasonable opportunity to address the issue before public disclosure, IINM will consider the circumstances when evaluating the reported activity.
Nothing in this policy grants permission to violate applicable law or to access systems beyond what is reasonably necessary to demonstrate a suspected vulnerability.
Public Disclosure
Please do not publicly disclose vulnerabilities, exploit details, affected user information, credentials, screenshots containing sensitive information, source code or other confidential information before coordinating with IINM.
IINM may request reasonable time to investigate and remediate a reported vulnerability before public disclosure.
Any public disclosure should avoid exposing personal information or details that could put IINM users or systems at additional risk.
No Guarantee of Reward
IINM does not currently guarantee monetary rewards, compensation, employment, recognition or any other benefit for vulnerability reports.
IINM may, at its discretion, recognise security researchers for responsible disclosures.
Any such recognition is entirely discretionary and does not create an obligation to provide compensation.
Privacy of Security Reports
Information submitted as part of a vulnerability report may be used to:
-
Investigate the reported vulnerability.
-
Communicate with the reporter.
-
Protect IINM systems and users.
-
Meet legal or regulatory obligations.
-
Improve security controls.
Personal information provided in a security report will be handled in accordance with the applicable IINM Privacy Policy.
Third-Party Services
Some IINM websites, applications or services may depend on third-party infrastructure, hosting providers, payment gateways, APIs, learning platforms or other external services.
Where a vulnerability is identified in a third-party service that is not controlled by IINM, IINM may need to coordinate with the relevant third-party provider.
IINM cannot guarantee remediation timelines for vulnerabilities that are exclusively within a third party's systems.
Legal Notice
This Responsible Disclosure Policy is intended to provide guidelines for good-faith security research.
Nothing in this policy:
-
Provides permission to violate applicable law.
-
Overrides contractual obligations.
-
Grants access to systems that you are not authorised to access.
-
Limits IINM's rights or remedies where unlawful activity occurs.
IINM reserves the right to modify this policy at any time.
Contact
For security vulnerabilities or responsible disclosure reports, please contact:
Indian Institute of Neuro Mind (IINM)
Phone:
+91 82829 56765
Office Address:
19 R.N. Mukherjee Road,
Hanuman Estates, Esplanade, B.B.D. Bagh,
Kolkata, West Bengal, India
Website:
https://iinmedu.com
Thank You
We appreciate responsible security researchers, developers and users who help us identify security issues and improve the safety of the IINM digital ecosystem.
Thank you for helping us keep IINM secure.
Indian Institute of Neuro Mind (IINM)
Last Updated: 27 August 2026
