Tata AIA - Vulnerability Disclosure Program (VDP) 

We are committed to maintaining the security and privacy of our systems, customers, and data. Our Vulnerability Disclosure Program enables security researchers and the public to responsibly report vulnerabilities.

banner-img

Scope

In Scope Out of Scope
  • Public-facing web applications
  • Mobile applications
  • APIs and services
  • Domains and subdomains owned/operated by our organization
  • Third-party integrations directly integrated with our systems
  • Third-party systems not controlled by us
  • Denial of Service (DoS/DDoS) attacks
  • Social engineering attacks
  • Physical attacks
  • Spam or automated scanning without validation

Program Rules

  1. Do not exploit vulnerabilities beyond proof-of-concept.
  2. Do not publicly disclose any vulnerabilities.
  3. Do not perform DoS/DDoS attacks or spamming activities.
  4. Do not compromise user privacy or personal data.
  5. Do not access financial or sensitive transactional information.
  6. Do not modify or delete any data.
  7. Do not conduct phishing, vishing, or impersonation.
  8. Only test systems within the defined scope.
  9. Do not share vulnerability details with third parties.
  10. Any misuse outside the defined scope is prohibited.
  • Program Guidelines

    • Who Can Participate
      Our program is open to external security researchers. Employees and contractors are not eligible.
    • Confidentiality
      All submissions are treated as confidential unless disclosure is required by law.
    • Safe Research
      We support good-faith security research and no legal action will be taken when guidelines are followed.
    • Expected Conduct
      Participants must follow ethical practices. Misuse may result in disqualification.
    • Program Updates
      We may update or discontinue the program at any time.
  • Reporting Process

    • When reporting a vulnerability, please include:
    • Detailed description of the issue

    • Steps to reproduce

    • Impact assessment

    • Proof of Concept (PoC)

    • Screenshots or logs (if applicable)

  • Submission Email

    Send your vulnerability report to:

    responsible-disclosure@tataaia.com

  • Consent Declaration

    By submitting this report, I confirm that I have adhered to the responsible disclosure guidelines and conducted testing in good faith within the defined scope. I understand that any violation of these guidelines may result in disqualification from the program and may be subject to appropriate legal action, where applicable.

  • Rewards & Recognition

    • Researchers may be listed in our Hall of Fame.

    • Exceptional reports may receive special recognition.

    • Recognition is based on impact and responsible disclosure.

Hall of Fame

We thank and recognize security researchers who responsibly disclose vulnerabilities and help improve our security posture.

Researcher Name

Alias / Handle

Date Recognized

Abderrahmen 

-

03-June-2026