Legal · Security

Responsible Vulnerability Disclosure Policy

PIEDAP Enterprise Ecosystem

Effective Date: 24 September 2026  |  Last Updated: 24 September 2026

Purpose

This policy provides a clear, safe and responsible process for reporting suspected security vulnerabilities affecting PIEDAP, its ecosystem services and Pion Global-controlled platform components. It is intended to help researchers and customers report vulnerabilities without causing harm to users, customers, data or service availability.

Policy at a Glance

TopicPIEDAP Position
Primary scopePIEDAP Enterprise Ecosystem, piedap.io and Pion Global-controlled production or public-facing components explicitly covered by this policy.
PlatformsGRCNest, NexGenQE, DPConsent, PIEStrat, EvalTiq and Talenaise, where the relevant service or component is operated or controlled by Pion Global and not governed by a more specific disclosure policy.
Research modelGood-faith, non-destructive security research using only public interfaces, researcher-owned accounts, authorized test environments or other expressly permitted access.
Reporting channelEmail [email protected] with subject: SECURITY VULNERABILITY REPORT. Do not send passwords, private keys or unnecessary personal data.
Disclosure modelCoordinated disclosure. Please allow Pion Global reasonable time to validate and remediate before public disclosure.
Bug bountyNo financial reward or bounty is promised unless Pion Global separately announces a written program.

1.Purpose and Principles

Pion Global Private Limited ("Pion Global", "we", "our" or "us") is committed to protecting the security, confidentiality, integrity and availability of the PIEDAP Enterprise Ecosystem and the information processed through it. Responsible vulnerability disclosure helps us identify and address security weaknesses that may not be found through internal testing alone.

This policy is designed to support responsible reporting, timely validation, coordinated remediation and constructive communication between Pion Global and security researchers, customers, partners and other finders of potential vulnerabilities.

Authorization notice: This policy does not authorize penetration testing, vulnerability scanning, exploitation, automated security testing or any other security testing of PIEDAP systems. Written authorization from Pion Global is required before conducting any such testing.

Industry alignment: The operating principles in this policy are informed by established vulnerability disclosure practices, including NIST SP 800-216, CERT-In responsible vulnerability disclosure guidance and RFC 9116 security.txt conventions.

2.Scope of the PIEDAP Ecosystem

PIEDAP is Pion Global's Enterprise Ecosystem. It brings together six specialized platforms and shared ecosystem capabilities such as identity, APIs, workflows, analytics, AI services, integrations, administration and developer services.

PlatformPrimary RoleSecurity Areas Potentially Relevant to Research
GRCNestGovernance, Risk & ComplianceAuthentication, authorization, tenant isolation, evidence handling, control workflows, integrations and reporting.
NexGenQEQuality EngineeringAuthentication, test data handling, integrations, automation flows, APIs, execution orchestration and tenant isolation.
DPConsentConsent & Privacy OperationsConsent records, data-subject workflows, authorization, privacy-data exposure, security integration and auditability.
PIEStratProject & Portfolio ManagementProject data, role permissions, workflow integrity, portfolio isolation, APIs, integrations and AI-assisted planning services.
EvalTiqAssessment & Decision IntelligenceAssessment data, evidence, scoring integrity, permissions, respondent confidentiality and analytics.
Talenaise360-degree Talent & Capability IntelligenceConfidential feedback, role access, identity, respondent privacy, report exposure and evaluation workflow integrity.

3.Systems Generally In Scope

Subject to the rules in this policy, the following are generally eligible for responsible reporting when they are operated on or controlled by Pion Global:

  • https://www.piedap.io and Pion Global-controlled subdomains used for the PIEDAP website, application access, APIs, documentation or developer services.
  • PIEDAP shared ecosystem services such as authentication, authorization, tenant management, workflow services, AI-enabled features, webhooks, integration services and shared analytics where accessible through authorized interfaces.
  • GRCNest, NexGenQE, DPConsent, PIEStrat, EvalTiq and Talenaise application components that are delivered as part of PIEDAP or explicitly reference this policy.
  • PIEDAP sandbox, trial or proof-of-concept environments only where the researcher has been authorized to use that environment and tests only data and accounts they control.
  • Public APIs, SDKs, integration endpoints and developer-portal functions specifically made available by Pion Global.

A platform-specific or customer-specific security policy may narrow or supersede this scope. If there is uncertainty about whether a target is in scope, contact us before testing.

4.Systems and Activities Out of Scope

The following are not authorized under this policy unless Pion Global gives prior written permission:

  • Third-party websites, cloud services, SaaS applications, AI providers, payment providers, identity providers, repositories or infrastructure that are not owned or controlled by Pion Global, even when integrated with PIEDAP.
  • Customer-owned networks, applications, endpoints, data sources or environments connected to PIEDAP.
  • Employee devices, corporate offices, physical security controls or non-public internal systems.
  • Social engineering, phishing, vishing, smishing, pretexting, credential harvesting or attempts to deceive Pion Global personnel, customers, partners or users.
  • Denial-of-service, distributed denial-of-service, destructive load testing, resource exhaustion or other activity that may impair service availability.
  • Brute-force attacks, password spraying, credential stuffing or attempts to access accounts that you do not own or control.
  • Testing that requires accessing, changing, deleting, downloading or exfiltrating another customer's data or another person's personal data beyond the minimum evidence necessary to demonstrate vulnerability.
  • Physical attacks, hardware tampering, supply-chain attacks or attacks against third-party dependencies outside Pion Global's control.
  • Low-impact observations such as missing cosmetic headers, non-exploitable version disclosures, descriptive error messages without sensitive data, or best-practice recommendations without a demonstrated security impact.

5.Research Rules and Conduct

Security research within the scope of this policy must be conducted in a responsible, non-destructive and privacy-respecting manner. All researchers must:

  • Stop testing and report immediately if you encounter any indication of active exploitation, customer data exposure or a breach affecting real users.
  • Do not attempt lateral movement into other tenants, customers, projects, integrations or administrative areas after demonstrating the issue.
  • Do not establish persistence, create hidden accounts, install backdoors, maintain command-and-control access or modify production configurations unnecessarily.
  • Use automated scanners conservatively, at reasonable rates, and stop immediately if your activity affects performance or stability.
  • Do not exploit a vulnerability beyond what is necessary to establish its existence and impact.
  • Do not intentionally access sensitive personal data, secrets, credentials, cryptographic keys, confidential customer information or regulated data.
  • If sensitive data is encountered, stop testing, do not retain or share the data, and report the issue promptly.
  • Do not publicly disclose the vulnerability before Pion Global has had a reasonable opportunity to investigate and remediate it.

6.Security Testing Restrictions

The following testing methods require prior written authorization from Pion Global:

  • Large-scale vulnerability scanning, fuzzing or load testing against production systems.
  • Testing that may alter data integrity, trigger large volumes of notifications, create material operational cost or generate significant logs or traffic.
  • Exploitation that could execute arbitrary code, modify tenant configuration, access infrastructure metadata or obtain privileged credentials beyond a minimal proof of concept.
  • Testing of production integrations that may send data or commands to third-party systems.
  • Any activity involving real customer data that is not owned or controlled by the researcher.

7.AI, Agentic and Automation Security Research

PIEDAP may include AI-assisted, agentic or automation capabilities. Security research involving those capabilities is welcome when it identifies a concrete security boundary failure rather than merely an undesirable model response.

Examples of potentially valid AI-related security findings

  • Prompt injection or tool manipulation that leads to unauthorized data access, privilege escalation, cross-tenant exposure or execution of actions outside the user's authorized scope.
  • Agent or workflow behavior that can bypass access controls, security approvals or tenant boundaries.
  • Model, retrieval or connector behavior that exposes protected secrets, confidential customer content or data belonging to another tenant.
  • Insecure AI integrations, tool permissions, webhook actions or external connectors that create a reproducible security impact.
  • AI-generated actions that can be induced to modify, delete or transmit protected data without the required authorization.

Generally not security vulnerabilities by themselves

Inaccurate model output, hallucinations, subjective content quality issues, disagreement with a recommendation, or prompt-based content that does not bypass a security, privacy or authorization boundary.

8.Privacy, Customer Data and Sensitive Information

PIEDAP can process enterprise, assessment, project, quality, compliance, consent, talent and other customer information. Researchers must minimize exposure to personal or customer data.

  • Use synthetic test data whenever possible.
  • Do not copy, retain, publish or transmit Customer Data unless a minimal sample is strictly necessary to prove the vulnerability.
  • Redact personal data, credentials, tokens, secrets and confidential information from screenshots or reports whenever possible.
  • If you inadvertently access another customer's or individual's information, stop immediately and tell us what was accessed without further exploring the data.
  • Securely delete any inadvertently retained sensitive data after Pion Global confirms that it is no longer needed for investigation.

9.How to Report a Vulnerability

Reporting channel

Send reports to [email protected] with the subject line SECURITY VULNERABILITY REPORT. Please do not include passwords, private keys, access tokens or unnecessary personal data in the initial email.

A useful report should include, where available:

  • Your name or preferred researcher identifier and a reliable contact method.
  • The affected domain, URL, API endpoint, platform, feature or version.
  • A concise vulnerability title and description.
  • Clear reproduction steps using only the minimum necessary proof of concept.
  • Observed and expected behavior.
  • Potential security impact, affected roles or tenant boundaries.
  • Screenshots, request/response samples, logs or other evidence with sensitive data redacted.
  • Any temporary mitigation you identified.
  • Whether you believe the issue is being actively exploited or presents an immediate risk.

10.PIEDAP Vulnerability Handling Process

StageTargetWhat We Do
AcknowledgementWithin 3 business daysConfirm receipt where the report contains enough information and a valid contact method.
Initial triageTypically within 7 business daysValidate scope, reproducibility, severity and whether additional information is needed.
InvestigationRisk-basedAssign the issue to the relevant security, platform or engineering owner and determine affected components.
RemediationRisk-basedDevelop, test and deploy fixes or compensating controls based on severity, exploitability and customer impact.
Researcher updatesAs appropriateProvide meaningful status updates when practical, particularly for validated high-impact findings.
ClosureAfter mitigationConfirm remediation status where appropriate and coordinate disclosure, acknowledgement or CVE steps if applicable.

These are operational targets, not contractual service levels. Complex issues, third-party dependencies, coordinated release requirements or active incidents may require additional time.

11.Severity and Prioritization

PIEDAP prioritizes vulnerabilities based on the actual security impact and context. Factors may include exploitability, authentication requirements, tenant isolation impact, confidentiality, integrity, availability, affected data, privilege level, attack complexity, active exploitation and the number of customers or systems exposed.

We may use industry-standard severity frameworks such as CVSS as one input, but final prioritization may also consider PIEDAP-specific architecture, customer exposure and compensating controls.

12.Coordinated Disclosure

We ask researchers to coordinate public disclosure with Pion Global. As a general target, we aim to resolve validated vulnerabilities within a reasonable period and may use a 90-day coordination window as a reference point where appropriate. The actual timeline may be shorter or longer depending on severity, active exploitation, third-party dependencies, customer deployment requirements and the complexity of remediation.

Please do not publish exploit details, proof-of-concept code, sensitive screenshots or customer information before an agreed disclosure date or before Pion Global has had a reasonable opportunity to mitigate the issue.

13.Good-Faith Research and Safe Harbor

If you make a good-faith effort to comply with this policy, avoid privacy harm and service disruption, and promptly report a vulnerability through the stated process, Pion Global intends to treat your activity as authorized security research for purposes of this policy and will not initiate legal action solely because of an accidental, limited policy violation made in good faith.

This safe-harbor statement does not protect conduct that is malicious, extortionate, fraudulent, intentionally destructive, outside the stated scope, unlawful, or harmful to customers, users, Pion Global or third parties. It also does not bind third parties whose systems you may interact with. If you are uncertain whether a test is permitted, contact us first.

No extortion: Threats of publishing data, disrupting services or demanding payment in exchange for withholding disclosure are not good-faith security research and are not protected by this policy.

14.Recognition and Bug Bounty

PIEDAP does not promise financial rewards, bounties, gifts or compensation under this policy unless Pion Global separately publishes a written bounty program that expressly applies to the reported issue. We may, at our discretion and with the researcher's permission, acknowledge researchers who make meaningful responsible disclosures.

15.CVE and CERT-In Coordination

Where appropriate, Pion Global may coordinate with relevant vendors, CVE Numbering Authorities, CERT-In, other national CERTs, customers or affected technology providers. This may be necessary when a vulnerability affects shared components, third-party dependencies, widely deployed software or multiple organizations.

A researcher should not independently disclose Customer Data or confidential PIEDAP information to third parties unless required by law or coordinated with Pion Global. Nothing in this policy prevents lawful reporting to an appropriate government or regulatory authority.

16.Third-Party Components and Integrations

PIEDAP integrates with external cloud, identity, engineering, collaboration, enterprise application, AI and other technology providers. If a reported issue appears to originate in a third-party component, Pion Global may share the minimum necessary technical information with that provider so the issue can be validated and resolved. Researchers should avoid testing the third party directly unless they are separately authorized under that party's disclosure policy.

17.security.txt

PIEDAP may publish a machine-readable security.txt file at /.well-known/security.txt on applicable domains to help researchers locate the current vulnerability reporting contact and policy. A security.txt file is intended to complement, not replace, this policy.

18.Policy Changes

Pion Global may update this policy to reflect changes in the PIEDAP architecture, platform scope, security processes, reporting channels or applicable requirements. The current version will be published on the PIEDAP website with an updated effective date. Material changes may also be communicated through appropriate customer or developer channels.

19.Contact

ItemDetails
OrganizationPion Global Private Limited
EcosystemPIEDAP Enterprise Innovation & Assurance Ecosystem
Security Reporting[email protected]
Websitehttps://www.piedap.io
Business Address48, 4th B Main, Classic Paradise Layout, Begur Road, Bengaluru, Karnataka, India
This policy is intended to facilitate responsible vulnerability reporting. It is not a bug bounty offer, penetration-testing authorization beyond its stated scope, or a waiver of rights for malicious or unlawful activity.