Standards
Security and responsible disclosure
Security is treated as an operating practice: minimize data, restrict access, verify behavior and make failures safe.
Last updated: 28 August 2026
Website controls
The rebuilt website limits third-party code, applies restrictive browser headers, bounds form input, uses Netlify’s form detection and spam controls, keeps submissions behind authenticated site administration and exposes no public lead-read endpoint.
What not to send
Do not submit passwords, payment-card details, government identifiers, health information or confidential client data through the project form.
Report a vulnerability
Email deepak@kalpixa.com with “Security report” in the subject. Include the affected URL, reproduction steps and impact. Do not access other people’s data, degrade the service, use social engineering or publish details before we have had a reasonable opportunity to investigate.
Response
We will acknowledge a credible report, triage it and communicate remediation progress where possible. This page does not create a bug-bounty program or authorize unlawful testing.