ਕਾਨੂੰਨੀ
ਸੁਰੱਖਿਆ ਖੁਲਾਸਾ
ਪੂਰੀ ਨੀਤੀ ਅੰਗਰੇਜ਼ੀ ਵਿੱਚ ਹੈ ਅਤੇ ਕਾਨੂੰਨੀ ਤੌਰ ’ਤੇ ਉਹੀ ਲਾਗੂ ਹੁੰਦੀ ਹੈ। ਹੇਠਾਂ ਦਿੱਤਾ ਪੰਜਾਬੀ ਸੰਖੇਪ ਸਹੂਲਤ ਲਈ ਹੈ; ਇਹ ਨੀਤੀ ਦੀ ਥਾਂ ਨਹੀਂ ਲੈਂਦਾ।
Effective — to supply —
ਸੰਖੇਪ
- ਸਾਈਟ (kalamdigoonj.com) ਵਿੱਚ ਕੋਈ ਸੁਰੱਖਿਆ ਖ਼ਾਮੀ ਲੱਭੇ ਤਾਂ ਸਾਨੂੰ ਈਮੇਲ ਰਾਹੀਂ ਦੱਸੋ।
- ਨੇਕ-ਨੀਅਤੀ ਨਾਲ, ਹੇਠਾਂ ਦਿੱਤੇ ਨਿਯਮਾਂ ਅੰਦਰ ਰਹਿ ਕੇ ਦੱਸੋ। ਅਸੀਂ ਤੁਹਾਡੇ ਖ਼ਿਲਾਫ਼ ਕੋਈ ਕਾਨੂੰਨੀ ਕਾਰਵਾਈ ਨਹੀਂ ਕਰਾਂਗੇ।
- ਅਸੀਂ ਪੰਜ ਕੰਮਕਾਜੀ ਦਿਨਾਂ ਵਿੱਚ ਤੁਹਾਡੀ ਰਿਪੋਰਟ ਮਿਲਣ ਦੀ ਪੁਸ਼ਟੀ ਕਰਦੇ ਹਾਂ।
- ਸ਼ੁਰੂਆਤ ਵਿੱਚ ਪੈਸੇ ਵਾਲਾ ਕੋਈ ਇਨਾਮ (bug bounty) ਨਹੀਂ, ਪਰ ਧੰਨਵਾਦ ਅਤੇ, ਜੇ ਤੁਸੀਂ ਚਾਹੋ, ਜਨਤਕ ਪਛਾਣ ਜ਼ਰੂਰ।
1. Scope
Northview Productions Inc., a British Columbia company doing business as Kalam Di Goonj (“the Company”, “we”), welcomes good-faith security research on kalamdigoonj.com and its subdomains, covering the website, reader accounts, newsletter and submission flows, the APIs serving the site, and our PDF and audio delivery.
Readers trust us with accounts, subscriptions, and correspondence. Research that helps us protect that trust serves the Publication.
2. How to report
Email [email protected] with:
- what you found and where, including URLs, endpoints, and parameters;
- steps to reproduce it, in enough detail for us to see what you saw;
- the potential impact as you assess it;
- any proof of concept, limited to the minimum that demonstrates the issue;
- how to reach you for follow-up. A pseudonym is acceptable.
Report in English or Punjabi. We do not yet publish a PGP key; when we do, it will be linked here and in our security.txt file. Until then, ask us at the same address for a secure channel before sending sensitive details.
3. Our commitments to you
- Acknowledgement within five business days of receiving your report.
- We will investigate, report progress at reasonable intervals, and tell you when the issue is fixed.
- No legal action for good-faith research conducted within this policy. If you follow the rules of engagement in section 4, we will not initiate legal proceedings or law-enforcement complaints against you for your research, and we will treat your access as authorized by us for the purposes of that research. See section 7.
- We will not pursue you for a minor accidental overstep, provided you stop, tell us promptly, and delete anything you should not have retrieved.
- With your permission we will credit you, by name or handle, when we disclose the fix. If you prefer anonymity, we honour it.
4. Rules of engagement
Good-faith research requires, at minimum:
- Demonstrate rather than extract. Access, copy, or exfiltrate no more data than the minimum needed to demonstrate the issue, and delete what you retrieved once you have reported it.
- No privacy violations. Do not access, modify, or share other people’s accounts, personal information, or correspondence. Where a flaw exposes someone’s data, stop at the first confirmation and report.
- No service disruption. No denial-of-service, load testing, or resource exhaustion against production.
- No social engineering of our staff, contributors, or readers, and no phishing, physical intrusion, or attacks on people.
- Test accounts only. Use accounts you created for testing. Do not test against real readers’ accounts, including your own reader account where a test account will serve.
- Coordinated disclosure. Allow us reasonable time to fix the issue before any public disclosure, and coordinate the timing with us.
5. Out of scope
- Third-party services. Vulnerabilities in the systems of Stripe, Resend, Cloudflare, YouTube, or other providers should be reported to those providers under their own programs. We cannot authorize testing of systems that are not ours. Do tell us as well where our configuration of a provider is the problem.
- Volumetric findings, including DoS and DDoS results, rate-limit observations produced by flooding, and brute-force findings.
- Reports without security impact, including missing best-practice headers alone, version banners, and SPF or DKIM observations without a demonstrated spoofing path. Press and social matters go through our Contact channels.
6. No bug bounty
At launch we operate no paid bug-bounty program. We are a small reader-supported publication and will not promise money we cannot commit. What we offer is prompt handling, a fix, public acknowledgement if you want it, and our thanks. If a bounty program is introduced, its terms will appear on this page first.
7. Safe harbour
For research that complies with this policy, the Company: (a) authorizes the access involved for the purpose of security research under this policy; (b) waives, to the extent of that compliance, claims it could otherwise bring in respect of that access; and (c) will confirm, if asked by others, that the research was authorized. This safe harbour cannot bind third parties or public prosecutors, and it does not apply to research that breaches the rules in section 4.
8. Limits of this page
This page is an invitation to help, not an open licence. Activity outside these rules, including taking data beyond proof, disrupting service, or targeting people, is not authorized by this or any other page. A security report is not a privacy request or a complaint; those have their own channels.
9. security.txt
We publish a security.txt file at /.well-known/security.txt under RFC 9116, naming the contact above, this policy’s URL, and an expiry date we refresh at least annually.