Vulnerability Management Program Policy

Last Updated: August 28, 2026

This Vulnerability Disclosure Program Policy (“VDP Policy”) describes the process established by Learnyst Insight Private Limited (“Learnyst,” “Company,” “we,” “our,” or “us”) for security researchers, customers, users, and third parties to responsibly report potential security vulnerabilities affecting Learnyst systems, applications, products, infrastructure, or services.

Learnyst is committed to maintaining the confidentiality, integrity, availability, and security of its platforms, systems, infrastructure, and customer information. As part of our Information Security Management System (ISMS) and ISO/IEC 27001-aligned security practices, Learnyst encourages responsible vulnerability disclosure and collaborative security research conducted in good faith.

This Policy establishes guidelines for reporting vulnerabilities, defines acceptable testing practices, outlines Learnyst’s response process, and helps ensure that security concerns are addressed responsibly and efficiently.

1. Purpose

The purpose of this Vulnerability Disclosure Program Policy is to establish a clear, structured, and responsible process for identifying, reporting, assessing, and addressing potential security vulnerabilities affecting the Services, systems, applications, infrastructure, or information assets of Learnyst Insight Private Limited.

This Policy is intended to:

  • Encourage responsible and good-faith security research and coordinated vulnerability disclosure practices;

  • Provide security researchers, users, customers, and third parties with an appropriate channel for reporting potential security vulnerabilities;

  • Support the timely identification, validation, assessment, remediation, and mitigation of security risks and vulnerabilities;

  • Protect Learnyst users, customers, systems, infrastructure, applications, networks, and information assets from unauthorized access, misuse, disruption, or compromise;

  • Reduce potential harm arising from cybersecurity threats, vulnerabilities, security incidents, or malicious activities;

  • Promote continuous improvement of Learnyst’s security posture, risk management, and incident response capabilities; and

  • Support Learnyst’s commitment to information security, privacy, operational resilience, regulatory compliance, and ISO/IEC 27001-aligned security practices.

This Policy also aims to foster collaboration with the security community while ensuring that vulnerability research and disclosure activities are conducted responsibly, ethically, lawfully, and in a manner that minimizes risk to users, systems, and Services.

2.  Responsible Disclosure Expectations

Individuals participating in this Vulnerability Disclosure Program (“Researchers”) are expected to conduct all security research and disclosure activities in a responsible, ethical, lawful, and good-faith manner, with due regard for the security, privacy, and operational stability of Learnyst Insight Private Limited and its users, customers, systems, infrastructure, and services.

Researchers are expected to adhere to the following principles:

  • Refrain from any actions that could cause harm, disruption, degradation, unauthorized access, or adverse impact to Learnyst, its users, customers, systems, infrastructure, networks, or data;

  • Take reasonable and appropriate steps to avoid violations of privacy, exposure of personal data, service interruptions, or any unintended operational impact during security testing or research activities;

  • Report identified or suspected vulnerabilities promptly upon discovery, without unnecessary delay;

  • Provide clear, accurate, and sufficient technical information, including steps to reproduce, impact assessment, and relevant evidence, to enable effective validation, investigation, and remediation;

  • Maintain strict confidentiality regarding any discovered vulnerabilities and related information until Learnyst has had a reasonable opportunity to investigate, validate, and implement appropriate remediation measures;

  • Comply fully with all applicable local, national, and international laws, regulations, and legal obligations governing security testing, data protection, and disclosure activities;

  • Adhere at all times to the scope, limitations, and requirements set forth in this Policy, including any additional instructions or restrictions communicated by Learnyst.

Failure to comply with these expectations may result in exclusion from the program and may trigger appropriate legal, operational, or security responses where necessary.

3. Authorized Security Research Activities

Learnyst Insight Private Limited permits good-faith security research activities strictly for the limited purpose of identifying, validating, and responsibly disclosing legitimate security vulnerabilities that may affect its systems, applications, infrastructure, or Services.

Authorized security research must be conducted in a controlled, ethical, and non-disruptive manner and only to the extent necessary to demonstrate the existence of a potential vulnerability.

Permitted testing activities may include:

  • Testing authentication, authorization, and identity verification mechanisms to identify potential security weaknesses;

  • Identifying misconfigurations in applications, infrastructure, or security controls that may expose systems or data;

  • Testing for commonly recognized web and application security vulnerabilities, including those aligned with industry standards and frameworks;

  • Assessing access control mechanisms for potential privilege escalation or unauthorized access risks;

  • Evaluating session management controls for weaknesses such as session fixation, hijacking, or improper session invalidation;

  • Identifying instances of unintended exposure of sensitive information or improper data handling;

  • Reporting insecure coding practices, insecure system configurations, or implementation-level security flaws; and

  • Identifying vulnerabilities using generally accepted and industry-recognized security testing methodologies and frameworks.

All authorized testing must be performed in a manner that is strictly non-destructive and must not:

  • Disrupt, degrade, or impair the availability or performance of the Services;

  • Access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability; or

  • Cause any operational, security, or privacy impact to Learnyst, its users, customers, or systems.

Researchers must ensure that all activities remain within reasonable bounds of responsible security research and do not extend beyond what is necessary to validate and report the vulnerability.

  1. Prohibited Activities

Researchers and participants must not:

  • Access, modify, download, copy, disclose, or destroy data belonging to Learnyst, customers, users, or third parties;

  • Conduct testing that intentionally disrupts, degrades, damages, or impacts the availability or performance of Services;

  • Perform denial-of-service (DoS), distributed denial-of-service (DDoS), resource exhaustion, or stress-testing activities;

  • Use social engineering, phishing, impersonation, or physical attacks against Learnyst personnel, customers, or users;

  • Introduce malware, ransomware, malicious code, or unauthorized payloads;

  • Exploit vulnerabilities beyond the minimum extent necessary to demonstrate their existence;

  • Access accounts, systems, or information without authorization;

  • Conduct automated scanning or testing that generates excessive traffic or operational impact;

  • Publicly disclose vulnerabilities before Learnyst has had a reasonable opportunity to investigate and remediate the issue;

  • Violate privacy, confidentiality, intellectual property, or applicable legal rights; or

  • Engage in extortion, threats, ransom demands, or coercive disclosure practices.

Any activity inconsistent with this Policy, applicable laws, or responsible security research practices is strictly prohibited.

5. Reporting a Vulnerability

Security vulnerabilities, suspected security weaknesses, or other security-related concerns relating to the Services provided by Learnyst Insight Private Limited may be reported to Learnyst through the following contact channel:

Email: support@learnyst.com

To assist Learnyst in efficiently validating, investigating, prioritizing, and remediating reported vulnerabilities, Researchers are encouraged to provide detailed and accurate information, including where applicable:

  • A clear and concise description of the identified vulnerability or security issue;

  • Detailed steps required to reproduce the issue;

  • Affected systems, applications, URLs, APIs, services, or components;

  • The potential impact, severity, or security implications of the vulnerability;

  • Supporting technical evidence such as screenshots, logs, payloads, proof-of-concept code, or other relevant materials where appropriate;

  • Information regarding any prerequisites, configurations, or conditions necessary to reproduce the issue; and

  • Contact information for follow-up communication or clarification purposes.

Researchers are encouraged to submit vulnerability reports promptly after discovery and to cooperate in good faith with Learnyst during the investigation and remediation process.

Learnyst requests that Researchers avoid public disclosure of reported vulnerabilities until Learnyst has had a reasonable opportunity to investigate, validate, and remediate the issue in accordance with responsible disclosure practices.

6. Learnyst Response Process

Upon receiving a vulnerability report submitted under this Vulnerability Disclosure Program, Learnyst Insight Private Limited may, at its discretion and in accordance with its internal security and incident management procedures:

  • Acknowledge receipt of the vulnerability report;

  • Review, assess, and validate the reported vulnerability or security concern;

  • Evaluate the severity, exploitability, potential impact, and associated risk to systems, users, customers, data, infrastructure, or Services;

  • Investigate confirmed vulnerabilities and determine appropriate remediation, mitigation, containment, or compensating measures;

  • Prioritize remediation efforts based on risk level, operational impact, technical complexity, and business considerations;

  • Communicate with the reporting party where reasonably appropriate to request additional information, provide status updates, or clarify technical details; and

  • Implement corrective, preventive, security enhancement, monitoring, or risk reduction measures as deemed necessary.

  • This Policy does not establish or guarantee any service-level agreements (SLAs), including but not limited to acknowledgment, status update, validation, investigation, remediation, or resolution timelines. Any indicative timelines (such as acknowledgment within 48 hours or status updates within 7 days) are provided on a best-effort basis only and do not constitute binding commitments or guarantees.

Learnyst may also use information obtained through vulnerability reports to improve its overall security posture, security controls, operational resilience, and incident response capabilities.

Response, investigation, mitigation, and remediation timelines may vary depending on several factors, including but not limited to:

  • The severity and potential impact of the vulnerability;

  • The complexity of investigation or remediation activities;

  • Technical architecture, dependencies, or infrastructure constraints;

  • Availability of remediation options or compensating controls;

  • Operational priorities and business impact; and

  • The risk posed to users, customers, systems, or Services.

While Learnyst makes reasonable efforts to address confirmed security vulnerabilities in a timely and risk-based manner, Learnyst does not guarantee specific response, investigation, validation, or remediation timelines under this Policy.

7. Confidentiality and Coordinated Disclosure

Researchers participating in this Vulnerability Disclosure Program are expected to maintain strict confidentiality regarding any reported vulnerabilities, security weaknesses, technical details, exploit methods, or related information until:

  • Learnyst Insight Private Limited confirms that the vulnerability has been remediated or sufficiently mitigated;

  • Learnyst provides explicit written authorization for public disclosure; or

  • A mutually agreed disclosure timeline or coordinated disclosure process has concluded.

Learnyst strongly encourages coordinated and responsible disclosure practices designed to minimize potential risks to users, customers, systems, applications, infrastructure, and Services.

Researchers must not publicly disclose, publish, share, demonstrate, or otherwise distribute information relating to identified vulnerabilities in a manner that could reasonably:

  • Expose users, customers, or systems to harm;

  • Facilitate exploitation, unauthorized access, or malicious activity;

  • Disrupt Services or operations; or

  • Compromise the confidentiality, integrity, or availability of Learnyst systems or data.

Where appropriate, Learnyst may work collaboratively with Researchers to coordinate responsible public disclosure following remediation or mitigation of the reported issue.

Unauthorized public disclosure of vulnerabilities prior to remediation, mitigation, or authorization by Learnyst may result in administrative, legal, contractual, or enforcement actions to the extent permitted under applicable laws and regulations.

8. No Compensation

Unless expressly agreed otherwise in writing by Learnyst Insight Private Limited, this Vulnerability Disclosure Program is intended solely as a responsible disclosure and security reporting mechanism and does not provide monetary rewards, bug bounty payments, financial incentives, reimbursements, or any other form of compensation for vulnerability submissions or security research activities.

Submission of a vulnerability report, participation in this Program, or communication with Learnyst regarding a reported issue does not create or imply:

  • Any contractual, employment, consulting, partnership, agency, joint venture, or fiduciary relationship;

  • Any entitlement to compensation, benefits, reimbursement, or remuneration;

  • Any transfer or grant of intellectual property rights, licenses, or ownership interests; or

  • Any obligation on the part of Learnyst to publicly acknowledge, reward, or compensate the reporting party.

Learnyst reserves the sole right and discretion to determine whether any form of recognition, acknowledgment, or discretionary reward may be offered in exceptional circumstances. Any such acknowledgment or reward, if provided, shall not establish any precedent or ongoing obligation.

9. Changes to this Policy

Learnyst Insight Private Limited reserves the right to modify, revise, update, or replace this Vulnerability Disclosure Program Policy from time to time to reflect:

  • Changes in applicable laws, regulations, regulatory guidance, or legal requirements;

  • Evolving cybersecurity threats, industry standards, security practices, or responsible disclosure frameworks;

  • Changes to Learnyst Services, systems, infrastructure, technologies, or operational processes; or

  • Updates to Learnyst’s security governance, risk management, compliance, or information security practices.

Updated versions of this Policy will be published through appropriate channels together with the revised effective date or “Last Updated” date.

Where appropriate or required by applicable law, Learnyst may provide additional notice regarding material changes through website notifications, platform communications, or other reasonable means.

Researchers and participants are encouraged to review this Policy periodically to remain informed of current requirements, responsibilities, and disclosure procedures.

Continued participation in vulnerability disclosure activities or continued interaction with the Program after the effective date of any revised Policy constitutes acknowledgment and acceptance of the updated terms, to the extent permitted by applicable law.

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved