Acceptable use
ThreatBharat exists to help defenders. These are the limits that keep it from being used against the people it reports on.
Effective
Do not use this platform to cause harm
Specifically, you must not use ThreatBharat or anything published on it to:
- Extort, threaten, or pressure an organisation or individual — including citing a report as leverage in a demand;
- Harass, dox, or target an individual named or implied in a report, including employees of an affected organisation;
- Locate, acquire, or trade stolen data. We publish that a claim exists; we do not publish routes to the data, and you may not use our reporting as a starting point to go and find it;
- Attack an organisation named in a report, or use our reporting to identify and exploit a target;
- Defame. A report describes a claim with a verification label. Presenting a claimed breach as an established fact, or stripping the caveat when quoting, is a misrepresentation of our work — see responsible publication.
Do not misrepresent what a report says
The verification label and confidence level are part of the finding, not decoration. When quoting or reproducing a report, keep them. Removing “claimed” or “unverified” changes the meaning and can cause real damage to an organisation that may have suffered nothing.
Do not present ThreatBharat as affiliated with a government body or regulator. It is not, and implying otherwise misleads people about the standing of what they are reading.
Automated access
- Respect
robots.txtand any rate limits you encounter. Rate limiting protects availability for everyone. - Do not scrape the site to build a competing or derivative dataset, or to mirror our reporting elsewhere.
- Do not attempt to enumerate identifiers, users, workspaces, or evidence objects. Every rejection returns the same “not found” response precisely so that it cannot be used to map what exists — treating that as a puzzle to solve is not good-faith research.
- Identify your automation honestly in its user agent, and give us a way to contact you.
Accounts
- Do not share credentials or let someone else use your account.
- Do not attempt to access another user’s data, another workspace, or a permission you have not been granted.
- Do not attempt to bypass authentication, multi-factor prompts, rate limits, or approval workflows.
Security testing
We welcome good-faith research into ThreatBharat itself. Report what you find to security@threatbharat.com and give us reasonable time to fix it before publishing.
In scope: our own web surfaces and API, tested against your own account and your own data.
Not in scope, and not acceptable:
- testing against another user’s account, another workspace’s data, or any published evidence you did not upload;
- denial of service, load testing, or anything that degrades availability for other users;
- social engineering of our staff, contributors, or providers;
- physical attacks, or attacks on our hosting or email providers;
- exfiltrating data to prove an issue. Demonstrate access and stop — do not download what you find.
If you access personal data accidentally during testing, stop, tell us, and delete it. We will treat a report made in good faith as a report, not as an incident against you.
Reporting misuse
If you see ThreatBharat content being used to extort, harass, or attack someone, tell us at contact@threatbharat.com. If a published report is itself the problem — wrong, unredacted, or unfair — use corrections and retractions.
Consequences
We may rate-limit, suspend, or block access, close accounts, and where appropriate refer conduct to the relevant authorities. We would much rather have a conversation first — if you are unsure whether something is acceptable, ask at contact@threatbharat.com before doing it.