Security Disclosure Policy
Examination infrastructure deserves adversarial scrutiny. If you believe you have found a security vulnerability in our website or platform, we want to hear from you — and we commit to engaging with good-faith reports seriously and respectfully.
How to report
Email gaurav@mgktech.in with the subject "Security disclosure", a description of the issue, steps to reproduce, and the potential impact as you understand it. Please give us a reasonable way to reach you for follow-up.
What we ask
Act in good faith: do not access, modify, or exfiltrate data belonging to examination authorities or candidates; do not degrade service availability; and do not test against live examinations. Give us reasonable time to remediate before any public disclosure.
What you can expect
Acknowledgement of your report, a genuine investigation, and updates as we triage and remediate. We will not initiate legal action against researchers who follow this policy in good faith.
We do not currently operate a paid bounty program; we do credit researchers who wish to be credited once an issue is resolved.
Scope
This website and ExamProdigy-operated platform infrastructure are in scope. Systems owned by examination authorities, and third-party services we do not control, are out of scope — reports affecting them will be passed to the relevant owner where possible.