UPDATES
LIVEVishwakarma Yojna upto 2 Cr
UPDATECGTMSE upto 2 Cr Collateral Free Business Loan
DEADLINEPMEGP Scheme: 35% Capital Subsidy के लिए शीघ्र Apply करें
FUNDINGGrants and Subsides upto 2 Cr for Women Entrepreneurs
TAX RELIEFMUDRA Loans upto 10 Cr for General category
NEWStartup Funding upto 50 Cr for SEZ units
LIVEVishwakarma Yojna upto 2 Cr
UPDATECGTMSE upto 2 Cr Collateral Free Business Loan
DEADLINEPMEGP Scheme: 35% Capital Subsidy के लिए शीघ्र Apply करें
FUNDINGGrants and Subsides upto 2 Cr for Women Entrepreneurs
TAX RELIEFMUDRA Loans upto 10 Cr for General category
NEWStartup Funding upto 50 Cr for SEZ units
LIVEVishwakarma Yojna upto 2 Cr
UPDATECGTMSE upto 2 Cr Collateral Free Business Loan
DEADLINEPMEGP Scheme: 35% Capital Subsidy के लिए शीघ्र Apply करें
FUNDINGGrants and Subsides upto 2 Cr for Women Entrepreneurs
TAX RELIEFMUDRA Loans upto 10 Cr for General category
NEWStartup Funding upto 50 Cr for SEZ units
BharatFundAxis Emblem
bharatfundaxis
SOVEREIGN GOVERNANCE & SECURITY DIRECTIVES

Privacy Policy & Security Directives

Comprehensive enterprise data protection frameworks, API resource usage terms, statutory compliance policies, and our official Vulnerability Disclosure Program.

Effective Date: August 02, 2026 • Legal Jurisdiction: Jaipur, Rajasthan, India. All corporate dispatches, TEV reports, and contact submissions processed by BharatFundAxis are governed under strict encryption, non-disclosure, and resource protection standards.

1. Scope & Sovereign Data Commitment

BharatFundAxis Capital Management ("BharatFundAxis", "We", "Our") respects the privacy and confidentiality of enterprises, founders, and institutional partners using our consulting platform. This Policy applies to all services, web portals, advisory desks, and digital endpoints operated under the BharatFundAxis platform.

We commit to maintaining sovereign data privacy standards in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000 of India.

2. Information We Collect

To evaluate scheme eligibility, prepare bankable Techno-Economic Viability (TEV) reports, and map non-dilutive credit lines, we collect the following categories of information:

  • Identity & Contact Details: Full name, official corporate email, contact telephone numbers, business address, and promoter credentials.
  • Enterprise & Financial Metrics: Business registration status (DPIIT, Udyam, MCA), turnover figures, capital requirement targets, and sector classifications.
  • Technical & Log Data: Originating IP address, browser metadata, time-stamps, and request headers collected automatically for security logging and rate-limiting purposes.

Zero Commercial Data Selling Policy: We do not sell, license, rent, or trade applicant contact information, financial metrics, or enterprise data to third-party marketing brokers or advertising networks under any circumstances.

OFFICIAL INFRASTRUCTURE SECURITY DIRECTIVE

3. Resource Protection & The "Don't Be That Guy" Policy

> root@bharatfundaxis:~# tail -f /var/log/waf/blocked_kiddies.log
"Oops! Did you just try to run DirBuster with 500 threads on a mostly static site? Adorable. We love the enthusiasm, but let’s set some boundaries before our automated sentinels null-route your entire ASN."

We are building an institutional-grade platform. Right now, it might look light, but our enterprise Web Application Firewalls (WAF) and real-time behavioral anomaly detectors are fully awake and highly caffeinated. We have a zero-tolerance policy for lazy, noisy infrastructural abuse. You want to test us? Be elegant about it.

Automated Scraping & Ghost Hunting

Scraping a static site? Congratulations on downloading our HTML. But seriously, deploying aggressive crawlers, botnets, or automated scripts to hunt for hidden endpoints or harvest data will just get your IP permanently walled off.

Credential Stuffing & Blind Brute-Forcing

Trying to brute-force /admin panels that don't even exist yet? Bold strategy. Any attempts to execute credential stuffing or manipulate session tokens will trigger our tarpits. We will slow your requests down to a crawl before dropping them completely.

DDoS Isn't Hacking, It's Just Being Loud

Any attempt to spam our contact endpoints, flood submission forms, or consume system resources via Layer 4/Layer 7 volumetric attacks is strictly prohibited. Sending a million requests a second doesn't make you a hacker; it makes you a nuisance to our society. Our automated systems track request velocity meticulously. Offending IP ranges won't just be banned—we actively bundle the logs and hand them over to CERT-In (Computer Emergency Response Team - India).

*Legitimate users & researchers: Did you accidentally get yourself blocked because your Burp Intruder was set to "greed"? Disable your aggressive VPNs, check your headers, and wait out the temporary ban. If it's a permanent ban, well... you should have read the rules first.
Security Operations Center : The Arena

4. Responsible Vulnerability Disclosure Program (VDP)

Welcome to the game. Right now, BharatFundAxis is mostly a highly-optimized static fortress. Your only real playground is our contact forms and their direct APIs. Looks too easy? Don't get comfortable. We are scaling fast. Soon, we'll be shipping complex architectures, heavier endpoints, and massive institutional features. The attack surface is going to explode, and the competition between our engineers and your payloads is just getting started. Consider this the warm-up round.

Leave Your Calling Card (Or Get Dropped)

We hate analyzing anonymous scanner traffic. If you're going to poke around our house, ring the doorbell. You must include this custom HTTP header in all your testing requests. If our WAF catches you throwing payloads without this header, it assumes you're a mindless bot and autobans your IP before you can even say "Burp Suite". Don't let a simple regex ruin your day.

X-BFA-Hunter: @your_social_handle_or_hacker_alias

Target Scope

"Yeah, it's tight right now. But keep monitoring our DNS. We deploy new code often. More code = more bugs. Stay hungry."

  • *.bharatfundaxis.com/* (All current and future subdomains & direct endpoints)

The Good Stuff (In-Scope)

Show us your best moves. Since we are mostly static right now, get creative with our forms and mailing architecture:

  • Creative API abuses on contact/submission endpoints
  • Stored / Reflected Cross-Site Scripting (XSS) with actual impact
  • Server-Side Request Forgery (SSRF) on any future integrations
  • Future Auth/Privilege bypasses (when we launch them)
  • Significant Business Logic Flaws that make us look dumb

The Trash Bin (Out-of-Scope)

Please, for the love of root, don't send us Nessus or Nuclei automated HTML reports:

  • Missing HTTP headers (We know. We don't care without a PoC)
  • Clickjacking on pages with no sensitive actions
  • Volumetric attacks / DDoS (Crashing a site with 10M requests isn't hacking)
  • Social Engineering our team (We already have trust issues)
  • SSL/TLS cipher weaknesses that require a quantum computer to break
Submission Protocol
Email your detailed report to support@bharatfundaxis.com. Give us clear reproduction steps. If your exploit chain requires us to guess what you did, we will close it as N/A. Send a PoC that actually works on the first try.
Bounty & Hall of Fame (Make Us Sweat)
Let’s be clear: This is a VDP, not a guaranteed cash-grab Bug Bounty. Financial rewards are strictly discretionary. If you submit a low-hanging fruit, you get a polite "Thanks." But if you manage to completely bypass our defenses and achieve something critical down the line? We’ll talk rewards. Make our SOC team cry a little, and we'll make it worth your while.
Rules of Engagement
  • Don't break the toys while you play. Test on your own data.
  • Give us at least 30 days to patch before you go dropping 0-days on Twitter/X to boost your clout.
  • If you accidentally stumble into sensitive infrastructure, stop immediately and report it. Don't go exploring.
Safe Harbor (The Truce)
It’s a simple trade. You hack us ethically according to these rules, and we give you Safe Harbor. We won't call the cyber police or unleash the lawyers on you. You go rogue? The truce is off. Happy hunting.

5. Data Retention & Storage Locations

All corporate records, grant evaluation archives, and advisory communications are stored on secure servers located within the Republic of India. Data is retained strictly for the duration necessary to fulfill advisory mandates or to satisfy statutory record-keeping obligations under Indian law.

6. Your Rights & Legal Jurisdiction

Under applicable Indian statutory provisions, applicants maintain rights to access, rectify, or request deletion of their submitted advisory records, subject to ongoing statutory audit mandates.

Legal Jurisdiction: This Privacy Policy and all associated data governance disputes are governed exclusively by the laws of India, with exclusive jurisdiction vested in the competent courts of Jaipur, Rajasthan, India.