Skip to Content

Security Disclosure Policy


To maintain the highest standards of safety and transparency, this policy establishes the protocols for identifying and addressing security concerns within RANNG’s operations. By engaging with our services, you agree to the framework for responsible disclosure and accountability detailed herein, fostering a secure and professional environment for all our partners and stakeholders.

Home     Legal and Compliance


Last Update: 01/07/2025



1. Purpose


RBV Lifestyle Private Limited, trading as RANNG ("RANNG," "we"), takes the security of our systems seriously. This policy explains how to report a suspected vulnerability to us responsibly, and what protection you get for doing so in good faith.

2. Scope


This policy covers: 

ranngglobal.com and any RANNG-branded subdomains. 

• Public-facing forms and functionality on those domains.

This policy does NOT cover: 

• Vulnerabilities in the underlying Odoo platform itself (RANNG's website runs on Odoo Online, a managed SaaS platform) — please report platform-level issues to Odoo S.A. through their own security process, not RANNG. 

• Third-party services we link to but don't operate. 

• Social engineering or phishing attempts against our staff. 

• Physical security of our premises. 

• Denial-of-service (DoS/DDoS) testing, load testing, or disruptive automated scanning.

3. How to Report a Vulnerability


Please report suspected vulnerabilities to: SECURITY CONTACT

Please include: 

• A description of the issue and its potential impact. 

• Steps to reproduce it. 

• The affected URL(s). 

• Any relevant environment details (browser, device). 

• Whether you'd like public credit for the finding. 

Please don't include more personal data than necessary to demonstrate the issue — data minimization applies to your report too.

4. Safe Harbor


We will not pursue legal action against researchers who report a vulnerability in good faith, provided you: 

• Avoid privacy violations, and don't access, modify, or exfiltrate more data than necessary to demonstrate the issue. 

• Report the issue to us promptly. 

• Give us reasonable time to remediate before any public disclosure. 

• Comply with applicable law throughout your research.

5. What We Ask You Not to Do


• Denial-of-service or load testing. 

• Accessing, modifying, or deleting data beyond what's needed to demonstrate the vulnerability. 

• Unauthorised access to accounts or systems beyond the scope of your own test. 

• Social engineering or phishing our staff, clients, or suppliers. 

• Publicly disclosing a vulnerability before we've had a reasonable opportunity to fix it.

6. Our Response Process


We aim to acknowledge reports within 7 days, and provide an initial assessment within 14 business days. Remediation timelines vary depending on severity and complexity.

7. Coordinated Disclosure and Recognition


Once a reported issue is remediated, we're happy to coordinate public disclosure with the researcher, and to credit you for the finding if you'd like — or keep your report anonymous, if you'd prefer.

8. No Bounties


RANNG does not currently offer monetary rewards for vulnerability reports, unless explicitly stated otherwise for a specific program. We're glad to offer public recognition where a researcher would like it.

9. Contact


RBV Lifestyle Private Limited (RANNG) 

PLOT NO 326, UDYOG VIHAR PHASE IV, Phase IV, Sector 19, 122016, GURUGRAM Haryana India

Security: SECURITY CONTACT