Back to CtrlOps
Security

CtrlOps Vulnerability Disclosure Policy

Last Updated: August 26, 2026

Security matters to us, and it matters even more for a tool that helps people manage their servers. If you are a security researcher and you find a vulnerability in CtrlOps, we want to hear about it, and we want to make it safe and simple for you to tell us.

This policy explains how to report a security issue to CtrlOps (a product of TST Tech Matrix Pvt Ltd), what we promise in return, and the rules we ask you to follow.

01. Our commitment

We welcome reports from security researchers acting in good faith. We will read every report, work with you, fix valid issues promptly, and treat you with respect throughout. This policy is our open invitation to help us keep CtrlOps and its users safe.

02. How to report

Please email your report to support@ctrlops.io with the subject line starting "Security:".

To help us act quickly, try to include:

  • A clear description of the issue and the impact you think it has
  • Steps to reproduce it, as detailed as you can
  • The affected area (for example, a URL, or the app and version)
  • Any proof of concept, screenshots, or logs that help
  • How we can reach you for follow-up

You do not need a fancy format. A clear plain-text email is perfect.

03. What is in scope

You may test and report issues on:

  • ctrlops.io and its subdomains
  • The CtrlOps desktop application

04. What is out of scope

Please do not test or report the following:

  • Third-party services we use, such as Razorpay, Creem, Brevo, Mixpanel, Tawk.to, and Google. Report those to the vendor directly.
  • Social engineering of our team, customers, or vendors
  • Physical attacks against our staff or offices
  • Denial-of-service (DoS) testing or anything that degrades or disrupts the service

Some reports usually do not qualify on their own, unless you can show a real, working security impact: results from automated scanners with no proof of concept, missing "best practice" security headers, self-XSS, clickjacking on pages with no sensitive action, rate-limiting suggestions, and reports of outdated software versions without a demonstrated exploit.

05. The rules we ask you to follow

To keep your research in good faith, please:

  • Do no harm. Do not access, change, delete, or save data that is not yours.
  • Respect privacy. If you come across someone else's personal data, stop, and tell us.
  • Do not disrupt the service or degrade the experience for other users.
  • Only test what is in scope, and only your own accounts and data.
  • Report promptly once you find something, and do not stockpile issues.
  • Do not extort. Threatening to release or withhold a report for payment is not good-faith research and is not covered by this policy.

06. Please keep it confidential

Please keep any issue you find confidential and do not disclose it publicly, in whole or in part, without our prior written consent. We will work with you on if and when anything can be shared. In return, we commit to fixing valid issues promptly and keeping you updated until they are resolved.

07. Our safe harbor promise

This is the important part. If you make a good-faith effort to follow this policy, we consider your security research authorized.

  • We will not pursue or support legal action against you for research that follows this policy.
  • We will treat your actions as authorized under the laws that would otherwise restrict them.
  • If someone else brings a claim against you for activity that followed this policy, we will make it known that your actions were authorized by us.

If you are ever unsure whether something is allowed, ask us first at support@ctrlops.io, and we will be glad to clarify.

08. What you can expect from us

When you report in line with this policy, we will:

  • Acknowledge your report within 3 business days
  • Give you a first assessment within 10 business days
  • Keep you updated as we investigate and fix the issue
  • Credit you publicly for the discovery, if you would like that

09. Recognition and rewards

We do not run a fixed cash bug bounty. What we do offer:

  • A genuine thank-you and public credit for researchers who report responsibly, if you want it
  • Any reward is decided case by case through mutual discussion, and may include CtrlOps plans or licenses as a token of our thanks

Our appreciation for good-faith research is real, and we will always try to recognize it fairly.

10. Changes and contact

We may update this policy from time to time. When we do, we will update the "Last Updated" date above.

To report an issue or ask a question, email support@ctrlops.io.

TST Tech Matrix Pvt LtdMondeal Heights, B-1702, Sarkhej - Gandhinagar Hwy, Satellite, Ahmedabad, Gujarat 380015, India

Found a security issue?

Email us with the subject line starting "Security:". We acknowledge every report within 3 business days.

support@ctrlops.io

CtrlOps by TST Tech Matrix Pvt Ltd.