1. How to Report
Email contact@saudaa.co.in with the subject line SECURITY. Include the affected URL or endpoint, reproduction steps, and what an attacker could achieve. Proof-of-concept code or screenshots help.
2. What to Expect
We acknowledge reports within 3 business days, give an initial assessment within 7 days, and aim to remediate critical issues within 30 days. We will keep you updated and credit you publicly if you wish.
3. Scope
In scope: saudaa.co.in and its API. Out of scope: third-party services we do not control (Razorpay, Google, TradingView, market-data vendors), findings that require physical access or a compromised device, and issues in outdated browsers.
4. Rules of Engagement
Test only against accounts you own. Do not access, modify or exfiltrate other users’ data; stop as soon as you have proved a finding. Do not run denial-of-service or spam tests, do not use automated scanners at damaging volume, and do not socially engineer our staff or users.
5. Please Do Not Disclose Publicly
Give us a reasonable window to remediate before publishing. We will agree a disclosure date with you rather than delay indefinitely.
6. Recognition
We do not currently operate a paid bug bounty. We do offer public credit and, at our discretion, complimentary platform access for significant findings.
7. Known Reports We Do Not Need
Missing security headers with no demonstrated impact, rate-limit findings on unauthenticated public endpoints, self-XSS, email enumeration through timing alone, and reports generated solely by automated tooling without validation.