SECURITY & VULNERABILITY DISCLOSURE POLICY
Effective Date: September 1, 2026
Last Updated: September 1, 2026
Hetuluka (Proprietor: Palash Hazarika)
Madhupur, Narayanpur Block, Lakhimpur, Assam – 787033, India
1. Purpose
Hetuluka takes reasonable measures to protect its website, applications, LMS, systems, educational services and user information.
This Security & Vulnerability Disclosure Policy ("Security Policy") explains:
Our general security approach;
How security incidents may be reported;
What security researchers and users may and may not do when testing Hetuluka;
How Hetuluka may respond to vulnerabilities; and
Important limitations regarding security and availability.
This Policy supplements the Terms of Use and Privacy Policy.
2. Security Measures
Hetuluka may use reasonable technical, administrative and organizational safeguards appropriate to its services and risks.
Depending on the system or service, these may include:
Encryption/TLS for data transmitted between systems;
Secure authentication mechanisms;
Access controls;
Role-based permissions;
Password protection and secure password handling;
Monitoring and logging;
Security reviews and testing;
Backups and recovery measures;
Infrastructure and cloud security controls;
Protection against unauthorized access; and
Incident-response procedures.
The specific safeguards may change as Hetuluka's technology, providers and security practices evolve.
3. No Absolute Security Guarantee
Although Hetuluka takes reasonable security measures, no website, application, network, cloud service or electronic system can be guaranteed to be completely secure.
Accordingly, Hetuluka does not guarantee:
That the platform will always be secure;
That vulnerabilities will never exist;
That unauthorized access will never occur;
That every security incident will be detected immediately;
That third-party systems will always remain secure; or
That services will always be available without interruption.
Security measures may also depend partly on third-party providers.
4. Responsible Vulnerability Disclosure
Hetuluka welcomes responsible reports of genuine security vulnerabilities that could affect its systems, users or services.
Security researchers, users and other responsible parties may report suspected vulnerabilities to:
Please provide enough information for Hetuluka to understand and reproduce the issue where reasonably possible.
A useful report may include:
A description of the vulnerability;
The affected website, application or service;
Steps to reproduce the issue;
Security impact;
Relevant screenshots or technical information;
Proof of concept, where appropriate; and
Your contact information for follow-up.
5. Authorized Security Testing
Any security testing must be conducted responsibly and without causing harm.
Unless Hetuluka has expressly authorized testing, you must not:
Access another person's account;
Access private user data;
Steal credentials or authentication tokens;
Modify or delete data;
Upload malicious code;
Deploy malware;
Conduct denial-of-service attacks;
Perform destructive testing;
Conduct social engineering against staff or users;
Attempt physical access to Hetuluka facilities or infrastructure;
Attack third-party providers through Hetuluka;
Bypass security controls for unauthorized access;
Exfiltrate data; or
Disrupt educational services.
Testing must not interfere with students, educators, customers, staff or normal platform operations.
6. Stop Testing After Confirmation
If you discover a vulnerability that provides access beyond what is necessary to demonstrate the issue, you should:
Stop further access;
Avoid viewing or copying unnecessary information;
Avoid changing or deleting data;
Avoid accessing other accounts;
Securely delete any unintentionally obtained information where legally appropriate; and
Report the issue promptly to incident@hetuluka.com.
Please do not publicly disclose the vulnerability before giving Hetuluka a reasonable opportunity to investigate and address it.
7. Prohibited Security Activity
The following may be treated as abuse rather than responsible vulnerability research:
Unauthorized account access;
Credential theft;
Phishing;
Malware deployment;
Ransomware;
Data destruction;
Data exfiltration;
DDoS or denial-of-service activity;
Spam or mass automated requests intended to disrupt services;
Extortion;
Threats;
Selling stolen Hetuluka information;
Public disclosure of sensitive information;
Exploiting users;
Persistent unauthorized access; or
Deliberate disruption of the platform.
Hetuluka may take appropriate technical, contractual or legal action where necessary.
8. Security Incidents
If Hetuluka becomes aware of a security incident, it may take reasonable steps to:
Investigate the incident;
Contain or restrict affected systems;
Protect users;
Preserve relevant evidence;
Correct vulnerabilities;
Reset credentials or access where necessary;
Work with relevant service providers;
Notify affected parties where required or appropriate; and
Notify regulators or authorities where legally required.
The timing and content of any notification may depend on the nature of the incident and applicable law.
9. Third-Party Security
Hetuluka may use third-party services for functions such as:
Cloud infrastructure;
Hosting;
Databases;
Storage;
Payment processing;
Authentication;
Email/SMS;
Video delivery;
Analytics;
Security;
Application distribution; and
Other platform operations.
Third-party providers maintain their own systems, policies and security controls.
Hetuluka does not control every aspect of third-party infrastructure and cannot guarantee the security of systems outside its reasonable control.
10. User Responsibilities
Security is also a shared responsibility.
Users should:
Keep account credentials confidential;
Avoid sharing accounts;
Use secure devices and networks where possible;
Keep devices and browsers reasonably updated;
Avoid suspicious links or messages;
Report suspected account compromise;
Use official Hetuluka channels; and
Follow applicable security instructions.
Users should report suspected account compromise or security abuse to:
11. Phishing & Impersonation
Be cautious of messages claiming to be from Hetuluka.
Hetuluka may communicate through its official domain, platform and authorized communication channels.
Do not provide passwords, authentication codes or sensitive information to an unknown person claiming to represent Hetuluka.
Suspected phishing, impersonation or fraudulent activity may be reported to:
12. Vulnerability Handling
When a vulnerability is reported, Hetuluka may:
Confirm receipt;
Investigate the report;
Attempt to reproduce the issue;
Assess severity and impact;
Prioritize remediation;
Deploy a fix or mitigation;
Request additional information;
Restrict affected functionality; or
Take other reasonable protective measures.
Hetuluka does not guarantee a particular response time, remediation period or outcome.
13. No Automatic Reward
Submitting a vulnerability report does not automatically create an entitlement to:
Payment;
A reward;
Employment;
Public recognition;
A contract; or
Any other compensation.
If Hetuluka introduces a separate bug-bounty or security-researcher program in the future, that program's specific terms will apply.
14. Good-Faith Research
Hetuluka may consider the circumstances of responsible, good-faith security research when deciding how to respond to a report.
However, nothing in this Policy:
Grants permission to access systems without authorization;
Creates a contractual security-testing authorization;
Waives any legal rights;
Guarantees immunity from legal action; or
Overrides applicable law.
Any safe-harbor protection applies only if expressly provided by Hetuluka or applicable law.
15. Confidentiality
Security researchers and reporters should treat non-public vulnerability information as confidential.
Please do not publicly disclose:
Credentials;
Personal information;
Security tokens;
Private source code;
Exploitation details that could enable immediate abuse;
Internal security information; or
Other confidential information obtained during testing.
Hetuluka may request coordinated disclosure where appropriate.
16. Security Improvements
Hetuluka may continuously improve its security practices as its:
Platform grows;
User base changes;
Technology evolves;
Threat environment changes;
Third-party providers change; and
Legal or regulatory requirements develop.
Security controls may therefore be modified, replaced or strengthened without advance notice where reasonably necessary.
17. Policy Changes
Hetuluka may update this Security Policy when necessary to reflect:
New technologies;
New services;
Security improvements;
Changes in law;
Changes in vulnerability-reporting practices; or
Changes in third-party infrastructure.
The updated version will include a new Effective Date.
18. Security Contact
Security Incidents & Vulnerabilities
For ordinary account, course, payment or service issues, please use the relevant support or contact channel instead.
General / Legal
Grievance
Business Address:
Hetuluka (Proprietor: Palash Hazarika)
Madhupur, Narayanpur Block, Lakhimpur, Assam – 787033, India