Legal & Security

How rtapulse.com handles privacy, data, security, and responsible disclosure.

Security posture

The site is static and privacy-first. Data exposure is minimised in everything published here. No server-side processing, no user accounts, no stored submissions.

Static siteLeast privilege

Data handling

No cookies by default. No third-party tracking scripts. No analytics. If forms are ever added, they will be minimal-data and explicit about what is collected and why.

No trackingData minimisation

Cookies and tracking

This site sets no cookies. There are no advertising networks, no session tracking, and no fingerprinting scripts. Cloudflare handles CDN and DDoS protection at the network layer.

Cookie-freeCloudflare CDN

Content and liability

All content reflects personal views and professional experience. Nothing published here constitutes legal, financial, or regulatory advice. Verify against primary sources before acting on any information.

Personal viewsNot advice

Vulnerability Disclosure

How to report security issues for rtapulse.com, and what to expect in return.

Report a security issue

Email: sachin@rtapulse.com

  • Include the affected URL, steps to reproduce, and your assessment of the impact.
  • If you have a proof-of-concept, keep it minimal. No sensitive or third-party data.
  • If you want a reply, include your preferred contact details.

This is a personal site. Response is best-effort and depends on availability.

Scope

  • In scope: rtapulse.com content and configuration under direct control.
  • Out of scope: third-party platforms including GitHub, Cloudflare, and linked external sites.

Please do not

  • Run denial-of-service tests or automated scanning at scale.
  • Attempt to access or exfiltrate data that is not yours.
  • Social engineer or phish anyone associated with the site.

Safe harbour

If you act in good faith and follow these guidelines, no action will be pursued for your security research. If you are unsure whether an approach is acceptable, ask first via email before proceeding.

security.txt

Security contact is also published at /.well-known/security.txt.


Contact

Best channel is email. No mailing lists. No tracking.

sachin@rtapulse.comLinkedIn

Personal site. Views are my own.

What ऋतPulse means

rtapulse.com (ऋतPulse) combines ऋत (ṛta / ṛtá), order, rule, truth, rightness, with Pulse (a living signal of health). It reflects how I think GRC should work: not a quarterly scramble, but a steady rhythm, detect drift early, keep evidence ready, and translate risk into decisions leaders can act on.