Crest Intelligence systems process land-title records, encumbrance certificates and court filings that contain personal data of real individuals. Security issues here are not abstract — a leak is a disclosure of someone's property and identity records.
Do not open a public issue.
Email contact@crestintelligence.in with:
- what you found and where (repo, file, endpoint)
- how to reproduce it
- what an attacker could reach with it
We aim to acknowledge within 3 working days and to give you a remediation timeline within 10 working days.
Please give us a reasonable window to fix the issue before disclosing it publicly. We will credit you in the fix unless you prefer otherwise.
- Credential or API-key exposure in source, history, logs or CI
- Unauthorised access to parcel, party or case data
- Injection, SSRF, path traversal or deserialisation flaws in intake and report paths
- Broken access control between tenants or investigations
- Dependency vulnerabilities with a demonstrable path to exploitation
- Findings against Government of Tamil Nadu portals or eCourts. Those are third-party systems. Report them to the relevant authority, not to us.
- Rate-limiting or volumetric denial of service
- Missing hardening headers with no demonstrated impact
- Social engineering of our staff
These rules apply to everyone with commit access:
- Never commit secrets. API keys, tokens and credentials belong in
.env, which is gitignored in every repo.ANTHROPIC_API_KEYin particular must never be committed. - Never commit real personal data. No real names, Aadhaar or PAN numbers, phone numbers, addresses, or unredacted document scans — not in code, fixtures, test data, issues, or pull request descriptions. Use synthetic parcels for tests.
- Never paste record extracts into an issue. Reference the case ID instead.
- If you commit a secret by accident, treat it as disclosed: rotate the credential first, then clean the history. Rotation comes first — removing the commit does not un-leak it.