सुरक्षा और भेद्यता प्रकटीकरण
अंतिम अद्यतन: 14 अगस्त 2026
यह सुरक्षा नीति केवल अंग्रेज़ी में प्रकाशित की जाती है। किसी भी विसंगति की स्थिति में अंग्रेज़ी संस्करण मान्य होगा।
We welcome reports from security researchers about vulnerabilities in the Kundli Saathi service. If you have found something, email us — we would rather hear it from you than from an attacker.
Report a vulnerability by email to security@kundlisaathi.com.
What we commit to
- Acknowledge receipt within 3 business days.
- Investigate and respond within 30 days for non-Sev1 issues, and within 7 days for Sev1.
- Coordinate disclosure — typically 90 days from your initial report, with extensions for complex issues agreed with you in writing.
- Credit you on our acknowledgments page unless you prefer to stay anonymous.
In scope
- The *.kundlisaathi.com web surface
- The app.kundlisaathi.com PWA and its mobile wrappers, once shipped
- The public REST API at api.kundlisaathi.com/v1/*, once shipped
- The /.well-known/* endpoints
- Our astro_engine service, where it is reachable from outside
Out of scope
- Third-party services we depend on — Dodo Payments, Razorpay, Anthropic, Sentry, Cloudflare and Supabase. Please report those directly to the vendor.
- Social engineering of staff.
- Physical attacks against infrastructure (we operate none of our own).
- Denial of service by volumetric attack. Please do not.
- Spam or phishing email impersonating us — forward those to phishing@kundlisaathi.com instead.
How to report
Email security@kundlisaathi.com with the subject line "[VDP] <one-line summary>" and include:
- Steps to reproduce
- The affected URL, endpoint or version
- Your assessment of severity
- The name or handle you would like credited — or tell us you prefer to stay anonymous
What not to do
- Do not exfiltrate or download data. A screenshot of a single record proving the vulnerability is fine; pulling the database is not.
- Do not modify, delete or persist data. Read-only proof of concept only.
- Do not run automated scans against production. If you need scale to demonstrate the issue, ask us first by email.
- Do not disclose publicly until we have coordinated. The standard timeline is 90 days, and we agree extensions in writing.
Safe harbour
If you act in accordance with this policy in good faith, we will:
- Not pursue legal action against you under the Information Technology Act 2000 §43/§66, the DPDP Act, the Computer Fraud and Abuse Act (US), or equivalent laws.
- Treat your report as authorised testing.
- Work with you to resolve the issue.
Severity guidance
| Severity | Examples |
|---|---|
| Sev1 | Authentication bypass, payment integrity issue, mass-PII access |
| Sev2 | Per-user PII access (single-user IDOR), CSRF on a payment-mutating route |
| Sev3 | Reflected XSS without auth bypass, information leak from error messages |
What happens after you report
- We acknowledge within 3 business days.
- We investigate. If the issue reproduces: Sev1 is fixed and you are notified within 7 days, with public disclosure at 30 days. Sev2 is fixed and notified within 30 days, disclosed at 90. Sev3 is fixed and notified within 60 days, disclosed at 180.
- We coordinate the timing of public disclosure with you.
- Once the issue is public we add you to the acknowledgments page, with your consent.
What we do not credit
Reports that reduce to missing security headers we deliberately do not set, rate-limit "attacks" within our published thresholds, or version disclosure from frameworks we already list publicly.
Media enquiries
For media questions about an already-public issue, write to press@kundlisaathi.com. Please do not use it for initial vulnerability reports — those belong at security@kundlisaathi.com, which is monitored for this purpose.
Acknowledgments
Researchers who report valid issues are listed on our acknowledgments page, unless they ask to remain anonymous.