Security & Vulnerability Disclosure
Last updated: June 12, 2026
Betaque Private Limited, operating the Closot brand (“Closot,” “we,” “our,” or “us”), takes the security of our products and our customers’ data seriously. This page describes how to report a security vulnerability, what to expect from us when you do, and the scope of our coordinated disclosure program.
1. Reporting a Vulnerability
If you believe you have found a security vulnerability in Closot, please report it to us by email at security@closot.com. Please include a clear description of the issue, the steps to reproduce it, the impact you believe it has, and any proof of concept or supporting material that helps us verify the finding quickly. If your report contains sensitive details, let us know in the first message and we will arrange an encrypted channel for the follow-up.
2. Our Commitments
When you submit a report in good faith, we commit to acknowledge receipt within two (2) business days, provide an initial assessment within seven (7) business days, keep you informed of remediation progress through resolution, and coordinate the timing of any public disclosure with you. We will not pursue legal action against researchers who follow this policy and act in good faith.
3. Scope
The following Closot-operated systems are within the scope of this program: the Closot web application at app.closot.com, the Closot API at api.closot.com, the Closot marketing site at closot.com, and the Closot Slack, GitHub, Gmail, and Google Calendar integrations operated by Closot. Vulnerabilities in third-party services that Closot integrates with (including Slack, Google, GitHub, MongoDB Atlas, AWS, and Vercel) should be reported to those providers directly.
4. Out of Scope
The following are not in scope and we ask that you do not test them: social engineering of Closot employees, customers, or partners; physical attacks against Closot offices or personnel; denial-of-service or volumetric attacks against production systems; automated scans that generate excessive traffic; vulnerabilities that require a fully compromised device, browser, or account belonging to another user; reports based solely on missing security headers, software version disclosure, or theoretical issues without a demonstrated impact; and findings in third-party services Closot does not operate.
5. Responsible Testing
We ask that you make every effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research. Only interact with accounts you own or have explicit permission to access. If you encounter any data belonging to another customer or user, stop testing immediately, do not retain, copy, or share that data, and notify us at once.
6. Recognition
Closot does not currently operate a paid bug bounty program. With your permission, we are happy to publicly thank researchers whose reports lead to a fix. If you would like to be credited, please let us know in your initial report and we will coordinate after the fix is deployed.
7. Contact
Security reports: security@closot.com. For postal correspondence on security matters, write to Betaque Private Limited, Attn: Security, Shop No 45, The Hub, opp. Prestige Institute, Scheme Number 78, Vijay Nagar, Part II, Indore, Madhya Pradesh 452010, India. The machine-readable version of this policy is published at /.well-known/security.txt in accordance with RFC 9116.