SECURITY & VULNERABILITY DISCLOSURE POLICY

Effective Date: September 1, 2026

Last Updated: September 1, 2026

Hetuluka (Proprietor: Palash Hazarika)
Madhupur, Narayanpur Block, Lakhimpur, Assam – 787033, India


1. Purpose

Hetuluka takes reasonable measures to protect its website, applications, LMS, systems, educational services and user information.

This Security & Vulnerability Disclosure Policy ("Security Policy") explains:

  • Our general security approach;

  • How security incidents may be reported;

  • What security researchers and users may and may not do when testing Hetuluka;

  • How Hetuluka may respond to vulnerabilities; and

  • Important limitations regarding security and availability.

This Policy supplements the Terms of Use and Privacy Policy.


2. Security Measures

Hetuluka may use reasonable technical, administrative and organizational safeguards appropriate to its services and risks.

Depending on the system or service, these may include:

  • Encryption/TLS for data transmitted between systems;

  • Secure authentication mechanisms;

  • Access controls;

  • Role-based permissions;

  • Password protection and secure password handling;

  • Monitoring and logging;

  • Security reviews and testing;

  • Backups and recovery measures;

  • Infrastructure and cloud security controls;

  • Protection against unauthorized access; and

  • Incident-response procedures.

The specific safeguards may change as Hetuluka's technology, providers and security practices evolve.


3. No Absolute Security Guarantee

Although Hetuluka takes reasonable security measures, no website, application, network, cloud service or electronic system can be guaranteed to be completely secure.

Accordingly, Hetuluka does not guarantee:

  • That the platform will always be secure;

  • That vulnerabilities will never exist;

  • That unauthorized access will never occur;

  • That every security incident will be detected immediately;

  • That third-party systems will always remain secure; or

  • That services will always be available without interruption.

Security measures may also depend partly on third-party providers.


4. Responsible Vulnerability Disclosure

Hetuluka welcomes responsible reports of genuine security vulnerabilities that could affect its systems, users or services.

Security researchers, users and other responsible parties may report suspected vulnerabilities to:

incident@hetuluka.com

Please provide enough information for Hetuluka to understand and reproduce the issue where reasonably possible.

A useful report may include:

  • A description of the vulnerability;

  • The affected website, application or service;

  • Steps to reproduce the issue;

  • Security impact;

  • Relevant screenshots or technical information;

  • Proof of concept, where appropriate; and

  • Your contact information for follow-up.


5. Authorized Security Testing

Any security testing must be conducted responsibly and without causing harm.

Unless Hetuluka has expressly authorized testing, you must not:

  • Access another person's account;

  • Access private user data;

  • Steal credentials or authentication tokens;

  • Modify or delete data;

  • Upload malicious code;

  • Deploy malware;

  • Conduct denial-of-service attacks;

  • Perform destructive testing;

  • Conduct social engineering against staff or users;

  • Attempt physical access to Hetuluka facilities or infrastructure;

  • Attack third-party providers through Hetuluka;

  • Bypass security controls for unauthorized access;

  • Exfiltrate data; or

  • Disrupt educational services.

Testing must not interfere with students, educators, customers, staff or normal platform operations.


6. Stop Testing After Confirmation

If you discover a vulnerability that provides access beyond what is necessary to demonstrate the issue, you should:

  1. Stop further access;

  2. Avoid viewing or copying unnecessary information;

  3. Avoid changing or deleting data;

  4. Avoid accessing other accounts;

  5. Securely delete any unintentionally obtained information where legally appropriate; and

  6. Report the issue promptly to incident@hetuluka.com.

Please do not publicly disclose the vulnerability before giving Hetuluka a reasonable opportunity to investigate and address it.


7. Prohibited Security Activity

The following may be treated as abuse rather than responsible vulnerability research:

  • Unauthorized account access;

  • Credential theft;

  • Phishing;

  • Malware deployment;

  • Ransomware;

  • Data destruction;

  • Data exfiltration;

  • DDoS or denial-of-service activity;

  • Spam or mass automated requests intended to disrupt services;

  • Extortion;

  • Threats;

  • Selling stolen Hetuluka information;

  • Public disclosure of sensitive information;

  • Exploiting users;

  • Persistent unauthorized access; or

  • Deliberate disruption of the platform.

Hetuluka may take appropriate technical, contractual or legal action where necessary.


8. Security Incidents

If Hetuluka becomes aware of a security incident, it may take reasonable steps to:

  • Investigate the incident;

  • Contain or restrict affected systems;

  • Protect users;

  • Preserve relevant evidence;

  • Correct vulnerabilities;

  • Reset credentials or access where necessary;

  • Work with relevant service providers;

  • Notify affected parties where required or appropriate; and

  • Notify regulators or authorities where legally required.

The timing and content of any notification may depend on the nature of the incident and applicable law.


9. Third-Party Security

Hetuluka may use third-party services for functions such as:

  • Cloud infrastructure;

  • Hosting;

  • Databases;

  • Storage;

  • Payment processing;

  • Authentication;

  • Email/SMS;

  • Video delivery;

  • Analytics;

  • Security;

  • Application distribution; and

  • Other platform operations.

Third-party providers maintain their own systems, policies and security controls.

Hetuluka does not control every aspect of third-party infrastructure and cannot guarantee the security of systems outside its reasonable control.


10. User Responsibilities

Security is also a shared responsibility.

Users should:

  • Keep account credentials confidential;

  • Avoid sharing accounts;

  • Use secure devices and networks where possible;

  • Keep devices and browsers reasonably updated;

  • Avoid suspicious links or messages;

  • Report suspected account compromise;

  • Use official Hetuluka channels; and

  • Follow applicable security instructions.

Users should report suspected account compromise or security abuse to:

incident@hetuluka.com


11. Phishing & Impersonation

Be cautious of messages claiming to be from Hetuluka.

Hetuluka may communicate through its official domain, platform and authorized communication channels.

Do not provide passwords, authentication codes or sensitive information to an unknown person claiming to represent Hetuluka.

Suspected phishing, impersonation or fraudulent activity may be reported to:

incident@hetuluka.com


12. Vulnerability Handling

When a vulnerability is reported, Hetuluka may:

  • Confirm receipt;

  • Investigate the report;

  • Attempt to reproduce the issue;

  • Assess severity and impact;

  • Prioritize remediation;

  • Deploy a fix or mitigation;

  • Request additional information;

  • Restrict affected functionality; or

  • Take other reasonable protective measures.

Hetuluka does not guarantee a particular response time, remediation period or outcome.


13. No Automatic Reward

Submitting a vulnerability report does not automatically create an entitlement to:

  • Payment;

  • A reward;

  • Employment;

  • Public recognition;

  • A contract; or

  • Any other compensation.

If Hetuluka introduces a separate bug-bounty or security-researcher program in the future, that program's specific terms will apply.


14. Good-Faith Research

Hetuluka may consider the circumstances of responsible, good-faith security research when deciding how to respond to a report.

However, nothing in this Policy:

  • Grants permission to access systems without authorization;

  • Creates a contractual security-testing authorization;

  • Waives any legal rights;

  • Guarantees immunity from legal action; or

  • Overrides applicable law.

Any safe-harbor protection applies only if expressly provided by Hetuluka or applicable law.


15. Confidentiality

Security researchers and reporters should treat non-public vulnerability information as confidential.

Please do not publicly disclose:

  • Credentials;

  • Personal information;

  • Security tokens;

  • Private source code;

  • Exploitation details that could enable immediate abuse;

  • Internal security information; or

  • Other confidential information obtained during testing.

Hetuluka may request coordinated disclosure where appropriate.


16. Security Improvements

Hetuluka may continuously improve its security practices as its:

  • Platform grows;

  • User base changes;

  • Technology evolves;

  • Threat environment changes;

  • Third-party providers change; and

  • Legal or regulatory requirements develop.

Security controls may therefore be modified, replaced or strengthened without advance notice where reasonably necessary.


17. Policy Changes

Hetuluka may update this Security Policy when necessary to reflect:

  • New technologies;

  • New services;

  • Security improvements;

  • Changes in law;

  • Changes in vulnerability-reporting practices; or

  • Changes in third-party infrastructure.

The updated version will include a new Effective Date.


18. Security Contact

Security Incidents & Vulnerabilities

incident@hetuluka.com

For ordinary account, course, payment or service issues, please use the relevant support or contact channel instead.

General / Legal

contact@hetuluka.com

Grievance

grievance@hetuluka.com

Business Address:
Hetuluka (Proprietor: Palash Hazarika)
Madhupur, Narayanpur Block, Lakhimpur, Assam – 787033, India