arrow_back Back to Home
Saudaa Logo

Responsible Disclosure

Last Updated: August 24, 2026

security Researchers Welcome

If you find a vulnerability, tell us privately and give us a chance to fix it. Act in good faith within this policy and we will not pursue legal action against you.

1. How to Report

Email contact@saudaa.co.in with the subject line SECURITY. Include the affected URL or endpoint, reproduction steps, and what an attacker could achieve. Proof-of-concept code or screenshots help.

2. What to Expect

We acknowledge reports within 3 business days, give an initial assessment within 7 days, and aim to remediate critical issues within 30 days. We will keep you updated and credit you publicly if you wish.

3. Scope

In scope: saudaa.co.in and its API. Out of scope: third-party services we do not control (Razorpay, Google, TradingView, market-data vendors), findings that require physical access or a compromised device, and issues in outdated browsers.

4. Rules of Engagement

Test only against accounts you own. Do not access, modify or exfiltrate other users’ data; stop as soon as you have proved a finding. Do not run denial-of-service or spam tests, do not use automated scanners at damaging volume, and do not socially engineer our staff or users.

5. Please Do Not Disclose Publicly

Give us a reasonable window to remediate before publishing. We will agree a disclosure date with you rather than delay indefinitely.

6. Recognition

We do not currently operate a paid bug bounty. We do offer public credit and, at our discretion, complimentary platform access for significant findings.

7. Known Reports We Do Not Need

Missing security headers with no demonstrated impact, rate-limit findings on unauthenticated public endpoints, self-XSS, email enumeration through timing alone, and reports generated solely by automated tooling without validation.