Security / Updated 07 August 2026
Report a security concern responsibly.
If you believe you have found a vulnerability affecting this website or domain, please report it privately with enough evidence to reproduce and assess the issue.
[email protected] ↗01
How to report
Email [email protected] with the subject “Security report for mashooqueadvisory.com”. Include the affected URL, a concise description, reproduction steps, observed impact and any supporting screenshots or request details with sensitive values removed.
Valid reports are normally acknowledged within two business days. Remediation timing depends on severity, reproducibility and third-party dependencies.
02
Scope
This policy covers the public website and resources served from mashooqueadvisory.com. Third-party services linked from the site—including Google Calendar, LinkedIn, Medium, Vercel and Cloudflare—are governed by their own security programmes and should be reported to the relevant provider.
03
Safe testing boundaries
- Use only accounts, systems and data you own or have explicit permission to test.
- Stop if you encounter personal, confidential or customer information and report the issue without retaining or sharing that data.
- Do not perform denial-of-service, destructive testing, social engineering, spam, physical testing, automated high-volume scanning or any action that degrades availability.
- Do not attempt persistence, data exfiltration, supply-chain compromise or access beyond the minimum needed to demonstrate the issue.
04
Good-faith handling
Reports made in good faith, within these boundaries and with reasonable time allowed for investigation will be handled constructively. Please keep vulnerability details confidential until a remediation or coordinated disclosure plan is agreed. This policy does not authorise unlawful activity, create a contract, or promise a reward or bug bounty.
05
Useful reports
Issues with a credible security impact are welcome. Reports limited to missing best-practice headers without demonstrated impact, self-XSS, clickjacking on pages with no sensitive action, outdated browser behaviour, rate-limit observations without impact, or automated scanner output without validation may not receive an individual response.