Responsible Disclosure Policy

Version 1.0 Effective: 30 July 2026 Last updated: 30 July 2026
All Legal & Compliance Pages

1. Purpose

We welcome reports from security researchers who discover a genuine vulnerability in the Stayvora Technologies platform, and are committed to working with researchers who report issues responsibly and in good faith.

2. Scope

This policy covers the platform at digital.stayvoratech.com and its subdomains/paths. It does not cover third-party services we integrate with (Razorpay, PhonePe, Meta/WhatsApp, etc.) — vulnerabilities in those should be reported directly to that provider.

3. How to Report a Vulnerability

Email support@stayvoratech.com with the subject line "Security Report," including a clear description of the vulnerability, steps to reproduce it, and its potential impact. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.

4. What to Expect

We aim to acknowledge a valid security report within 3 business days, and to keep you informed of our investigation progress. We do not currently operate a paid bug bounty program, but we are grateful for responsible reports and will credit researchers who wish to be credited, where appropriate.

5. Safe Harbor

We will not pursue legal action against a researcher who discovers and reports a vulnerability in good faith, in accordance with this policy, and who does not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability, does not perform denial-of-service testing, and gives us reasonable time to remediate before any public disclosure.