1. Purpose
RBV Lifestyle Private Limited, trading as RANNG ("RANNG," "we"), takes the security of our systems seriously. This policy explains how to report a suspected vulnerability to us responsibly, and what protection you get for doing so in good faith.
2. Scope
This policy covers:
• ranngglobal.com and any RANNG-branded subdomains.
• Public-facing forms and functionality on those domains.
This policy does NOT cover:
• Vulnerabilities in the underlying Odoo platform itself (RANNG's website runs on Odoo Online, a managed SaaS platform) — please report platform-level issues to Odoo S.A. through their own security process, not RANNG.
• Third-party services we link to but don't operate.
• Social engineering or phishing attempts against our staff.
• Physical security of our premises.
• Denial-of-service (DoS/DDoS) testing, load testing, or disruptive automated scanning.
3. How to Report a Vulnerability
Please report suspected vulnerabilities to: SECURITY CONTACT
Please include:
• A description of the issue and its potential impact.
• Steps to reproduce it.
• The affected URL(s).
• Any relevant environment details (browser, device).
• Whether you'd like public credit for the finding.
Please don't include more personal data than necessary to demonstrate the issue — data minimization applies to your report too.
4. Safe Harbor
We will not pursue legal action against researchers who report a vulnerability in good faith, provided you:
• Avoid privacy violations, and don't access, modify, or exfiltrate more data than necessary to demonstrate the issue.
• Report the issue to us promptly.
• Give us reasonable time to remediate before any public disclosure.
• Comply with applicable law throughout your research.
5. What We Ask You Not to Do
• Denial-of-service or load testing.
• Accessing, modifying, or deleting data beyond what's needed to demonstrate the vulnerability.
• Unauthorised access to accounts or systems beyond the scope of your own test.
• Social engineering or phishing our staff, clients, or suppliers.
• Publicly disclosing a vulnerability before we've had a reasonable opportunity to fix it.
6. Our Response Process
We aim to acknowledge reports within 7 days, and provide an initial assessment within 14 business days. Remediation timelines vary depending on severity and complexity.
7. Coordinated Disclosure and Recognition
Once a reported issue is remediated, we're happy to coordinate public disclosure with the researcher, and to credit you for the finding if you'd like — or keep your report anonymous, if you'd prefer.
8. No Bounties
RANNG does not currently offer monetary rewards for vulnerability reports, unless explicitly stated otherwise for a specific program. We're glad to offer public recognition where a researcher would like it.
9. Contact
RBV Lifestyle Private Limited (RANNG)
PLOT NO 326, UDYOG VIHAR PHASE IV, Phase IV, Sector 19, 122016, GURUGRAM Haryana भारत.
Security: SECURITY CONTACT