Reporting a security problem
Version 1 · in force from 20 August 2026 · how we change these documents
1. How to report
- 1.1 Email [email protected] with what you found.
- 1.2 Include the steps to reproduce it, the version of the app or the URL, and what you think the impact is.
- 1.3 Give us reasonable time to fix it before you make it public. Ninety days is a normal period.
2. What we do
- 2.1 We acknowledge within 72 hours.
- 2.2 We tell you what we found, and when it is fixed.
- 2.3 We will credit you if you want to be credited.
- 2.4 We do not run a paid bounty programme today.
3. What is not allowed
- 3.1 Do not access, change or delete anybody else’s data.
- 3.2 Do not run tests that degrade the service for other people, including denial of service and automated scanning at volume.
- 3.3 Do not use social engineering against our team or our providers.
- 3.4 Do not test physical security anywhere.
4. Out of scope
- 4.1 Findings from automated scanners without a working proof.
- 4.2 Missing best-practice headers with no demonstrated impact.
- 4.3 Problems in third-party services. Report those to them, and tell us as well.
Questions about this page
Write to [email protected], or call +91 70644 54262. We answer between 10am–7pm IST, Mon–Sat.
This page is one of the documents listed on our legal page. Older versions of it are kept in the archive.