We welcome reports from security researchers who discover a genuine vulnerability in the Stayvora Technologies platform, and are committed to working with researchers who report issues responsibly and in good faith.
This policy covers the platform at digital.stayvoratech.com and its subdomains/paths. It does not cover third-party services we integrate with (Razorpay, PhonePe, Meta/WhatsApp, etc.) — vulnerabilities in those should be reported directly to that provider.
Email support@stayvoratech.com with the subject line "Security Report," including a clear description of the vulnerability, steps to reproduce it, and its potential impact. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.
We aim to acknowledge a valid security report within 3 business days, and to keep you informed of our investigation progress. We do not currently operate a paid bug bounty program, but we are grateful for responsible reports and will credit researchers who wish to be credited, where appropriate.
We will not pursue legal action against a researcher who discovers and reports a vulnerability in good faith, in accordance with this policy, and who does not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability, does not perform denial-of-service testing, and gives us reasonable time to remediate before any public disclosure.