Lenskart Responsible Disclosure Program
Introduction:
Lenskart is committed to maintaining the safety and integrity of our products. We value the privacy of our customers and partners and understand the importance of critical data. We strive to protect our systems and data in accordance with best security practices and standards. While every effort is made to ensure the security of websites, mobile applications and internal systems, we welcome reports of vulnerabilities that can help further improve the security, integrity and privacy of our systems. We take every vulnerability disclosure seriously and are committed to creating a safe and transparent vulnerability reporting environment.
Bug bounty eligibility guidelines
- The identified vulnerability must be disclosed only to Lenskart. Do not share the vulnerability information to any party outside Lenskart without permission.
- Disclosure write-up should include clear details with steps to reproduce, verifiable proof of concept (screenshots, video, script), along with the clear security impact of the finding
- Early bird catches the worm. Be the first to report an issue. Duplicate reports will not be eligible for a bounty reward.
- Lenskart reserves the right to cancel or modify this program at any time without prior announcement.
- Lenskart reserves the sole right to determine the eligibility and severity of the vulnerability and its bounty reward.
- Reporters submitting a Vulnerability to Lenskart agree to be bound by the terms of the Vulnerability Disclosure Policy (“Terms“)
- We explicitly specify what is in scope and out of scope when discovering vulnerabilities and clearly mention the same in the sections below.
- Reporters should make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
- Reporters should only use/exploit to the extent necessary to confirm a vulnerability.
- Reporters should not use or exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use/exploit to “pivot” to other systems.
- Once a reporter establishes that a vulnerability exists, or encounters any sensitive data, the reporter should stop any further testing and notify us immediately.
- Reporters shall keep any information about discovered vulnerabilities confidential after submitting the vulnerability report.
- We discourage violation of any applicable laws and breach of any agreements in order to discover vulnerabilities.
- Lenskart reserves the right to pursue legal action when the terms of this policy is violated or when testing is performed outside the scope of this policy.
- Lenskart may include an NDA and also make updates to this policy from time to time.
- The decision made by our security team regarding validity, severity & impact of a vulnerability will be considered final and cannot be contested.
- We may share your vulnerability reports with any affected partners, vendors or open source projects.
In scope items:
- lenskart.com
- lenskart.us
- lenskart.ae
- johnjocobseyewear.com
- lenskartacademy.com
- aqualens.in
- Mobile App:
- Lenskart Android App available on Play store
- Lenskart iOS App available on App store
Reporting an issue
Vulnerabilities discovered on our systems while testing within the scope of this policy can be reported by emailing it to security@lenskart.com Please ensure that the following information is available when submitting a vulnerability report.
- Description of the location and potential impact of the vulnerability. Please include any CVEs when available.
- A detailed description of the steps required to reproduce the vulnerability. Proof of concept (POC) scripts, screenshots, and screen captures are all helpful.
Please use extreme care to properly label and protect any exploit code. - Any technical information and related materials we would need to reproduce the issue.
- If possible please include the contact details (email, mobile number) to let our Security team reach out to you for any clarifications.
Note that reports that include only crash dumps or other automated tool output will not be accepted.
Please keep your vulnerability reports current by sending us any new information as it becomes available. We may share your vulnerability reports with any affected partners, vendors or open source projects.
Out of scope:
- Any services not expressly listed In Scope, such as any connected services, partner & vendor websites are excluded from scope.
- Connected services
- Partner & vendor websites
- Vendor Endpoints
- Delivery App Endpoints
- Warehouse Endpoints
- 3rd Party Applications
- If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We may at our sole discretion, modify or amend the scope of this policy from time to time.
Recognition
Lenskart does not have a bounty/cash reward program for vulnerability disclosures, but we express our gratitude for your contribution in different ways. For genuine ethical disclosures, we will gladly acknowledge your contribution publicly in this section of our website. Of course, this will only be done if you want a public acknowledgement.
Eligibility for Hall of Fame
- Must be the first person to responsibly disclose the vulnerability
- Vulnerability discovered must be found when testing within the scope of this policy
- Reported vulnerability significantly impacts security and integrity of Lenskart products or impacts the privacy of customer or partner data.
- Vulnerabilities are rated Critical, High, Medium and low, Only vulnerabilities rated Critical and High are eligible for the Hall of Fame.