Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last Updated on July 19, 2026

Last Updated on July 19, 2026

Last Updated on July 19, 2026

Spatial Guide Private Limited ("Spatial Guide", "we", "our", or "us") recognizes that the security of our products and services benefits from collaboration with the broader security community. Independent security researchers, customers, partners, and members of the public often identify potential security vulnerabilities that may not be discovered through routine internal testing alone. We appreciate responsible efforts to identify and report security issues that could affect the confidentiality, integrity, or availability of our Services.

This Vulnerability Disclosure Policy describes the process for responsibly reporting suspected security vulnerabilities affecting Spatial Guide's products, cloud services, mobile applications, APIs, websites, digital twin technologies, Artificial Intelligence services, or supporting infrastructure. The objective of this Policy is to facilitate coordinated vulnerability disclosure while protecting our customers, users, and the broader technology ecosystem.

Spatial Guide is committed to investigating good-faith security reports promptly and to working collaboratively with security researchers to understand, validate, remediate, and responsibly disclose confirmed vulnerabilities where appropriate.

Scope

This Policy applies to publicly accessible products, websites, APIs, cloud platforms, mobile applications, and online services that are owned or operated by Spatial Guide.

Certain systems may fall outside the scope of this Policy, including third-party services, customer-managed deployments, proof-of-concept environments, legacy systems that are no longer supported, internal corporate systems not intended for public access, and infrastructure owned or controlled exclusively by our customers or cloud service providers.

Where a reported issue affects both Spatial Guide and a third-party provider, Spatial Guide may coordinate disclosure activities with the affected provider where appropriate.

Responsible Security Research

Spatial Guide welcomes good-faith security research conducted in a manner that minimizes operational disruption and protects the privacy and security of our customers.

Researchers are encouraged to conduct testing carefully and responsibly. Activities should be limited to those reasonably necessary to identify and demonstrate the existence of a potential vulnerability. Testing should avoid actions that could materially disrupt the availability of the Services, compromise Customer Data, interfere with normal business operations, or negatively impact other users.

Researchers should immediately discontinue testing if they inadvertently gain access to Customer Data or confidential information beyond what is reasonably necessary to demonstrate the reported issue. Such information should not be copied, modified, retained, disclosed, or otherwise used except as necessary to report the vulnerability to Spatial Guide.

Good-faith research conducted in accordance with this Policy will be treated as authorized for the purposes of vulnerability disclosure. However, this Policy does not authorize activities that violate applicable laws, contractual obligations, or the rights of third parties.

Activities That Are Not Permitted

To protect our customers and operational environments, this Policy does not authorize activities that intentionally disrupt the Services, compromise customer confidentiality, or create unnecessary operational risk.

Researchers should not intentionally access Customer Data, modify production information, create persistent accounts, perform social engineering against customers or employees, conduct phishing campaigns, introduce malicious software, perform denial-of-service attacks, attempt ransomware simulations, exploit vulnerabilities for personal gain, or publicly disclose vulnerabilities before Spatial Guide has had a reasonable opportunity to investigate and remediate the reported issue.

Similarly, automated testing that generates excessive traffic or materially affects platform availability should not be performed without prior written authorization from Spatial Guide.

Reporting a Vulnerability

Reports should be submitted as soon as reasonably practicable after the potential vulnerability has been identified. To facilitate efficient investigation, researchers are encouraged to include sufficient technical information describing the issue.

Useful information typically includes the affected product or service, the affected URL or API endpoint where applicable, the steps necessary to reproduce the issue, technical descriptions of the observed behavior, supporting screenshots or proof-of-concept material where appropriate, the potential security impact, software versions if known, and contact information that enables our security team to request clarification if necessary.

Providing clear and reproducible information significantly improves our ability to validate reported issues and reduce remediation timelines.

Our Commitment

Spatial Guide is committed to reviewing every good-faith vulnerability report received through the appropriate reporting channels.

Following receipt of a report, we generally acknowledge submissions within a reasonable period, evaluate the reported issue, determine whether additional information is required, assess potential impact, prioritize remediation activities according to risk, and communicate with the reporting researcher regarding the status of the investigation where appropriate.

Not every reported issue will ultimately be determined to represent a security vulnerability. Some reports may relate to intended functionality, operational limitations, duplicate findings, issues already under investigation, third-party systems, or matters that fall outside the scope of this Policy. Nevertheless, every report is reviewed in good faith and evaluated according to our internal security processes.

Coordinated Disclosure

Spatial Guide believes that coordinated vulnerability disclosure promotes better security outcomes for customers and the broader technology community.

Where a reported vulnerability is confirmed, we generally request that researchers refrain from publicly disclosing technical details until Spatial Guide has had a reasonable opportunity to investigate the issue, develop an appropriate remediation, deploy necessary updates, and notify affected customers where appropriate.

The timing of any coordinated public disclosure may depend upon the severity of the vulnerability, customer impact, technical complexity, deployment timelines, regulatory obligations, and coordination with affected third-party vendors.

Where appropriate and mutually agreed, Spatial Guide may acknowledge the contributions of security researchers following the responsible disclosure of confirmed vulnerabilities.

Legal Safe Harbor

Spatial Guide will not initiate legal action against security researchers who conduct good-faith research in accordance with this Policy, act responsibly, avoid causing harm, respect customer privacy, and promptly report discovered vulnerabilities through the designated reporting channels.

This commitment applies only to activities that remain within the scope of this Policy and applicable law. Activities that intentionally compromise Customer Data, disrupt Services, violate applicable laws, exploit vulnerabilities for unauthorized benefit, or otherwise exceed the scope of responsible security research remain outside the protections described in this Policy.

Researchers are expected to comply with all applicable laws and regulations within the jurisdictions in which they conduct their research.

Rewards

Unless expressly announced otherwise through a formal bug bounty or vulnerability reward program, submission of a vulnerability report does not create any entitlement to financial compensation, rewards, consulting engagements, or other consideration.

From time to time, Spatial Guide may establish separate vulnerability reward programs or public recognition initiatives subject to independent eligibility requirements and program terms.

Changes to this Policy

Spatial Guide may update this Vulnerability Disclosure Policy periodically to reflect changes in our products, operational practices, legal requirements, industry standards, or security processes.

Updated versions of this Policy will be published through our website or otherwise made available to interested parties. Continued participation in our vulnerability disclosure process following publication of an updated Policy constitutes acceptance of the revised version.

Contact Us

Security vulnerabilities should be reported directly to our security team using the contact information below.

Spatial Guide Private Limited

Email: security@spatial.guide

Website: https://www.spatial.guide

Please include "Security Vulnerability Report" in the subject line of your email whenever reasonably possible to assist with timely routing and investigation.

Spatial Guide

We design human-in-the-loop digital solutions that blend AI, immersive tech, and intelligent systems, built to drive real-world results across operations, training, and customer experience.

Contact Us

Whatsapp

+91 98484 39326

Call

+91 98484 39326

Email

contact@spatial.guide

Copyright © 2026 Spatial Guide. All Rights Reserved

Spatial Guide

We design human-in-the-loop digital solutions that blend AI, immersive tech, and intelligent systems, built to drive real-world results across operations, training, and customer experience.

Contact Us

Whatsapp

+91 98484 39326

Call

+91 98484 39326

Email

contact@spatial.guide

Copyright © 2026 Spatial Guide. All Rights Reserved

Spatial Guide

We design human-in-the-loop digital solutions that blend AI, immersive tech, and intelligent systems, built to drive real-world results across operations, training, and customer experience.

Contact Us

Whatsapp

+91 98484 39326

Call

+91 98484 39326

Email

contact@spatial.guide

Copyright © 2026 Spatial Guide. All Rights Reserved

Spatial Guide

We design human-in-the-loop digital solutions that blend AI, immersive tech, and intelligent systems, built to drive real-world results across operations, training, and customer experience.

Contact Us

Whatsapp

+91 98484 39326

Call

+91 98484 39326

Email

contact@spatial.guide

Copyright © 2026 Spatial Guide. All Rights Reserved