Skip to content

Legal

Security & Responsible Disclosure Policy

Last updated

In short

  • Data is encrypted in transit, passwords are hashed, and staff access is limited.
  • Report vulnerabilities to security@selectvia.com; we respond within 3 working days.
  • Good-faith research under this policy won't lead to legal action from us.

This summary is for convenience; the full text below is what applies.

1. How we protect data

  • All traffic is served over HTTPS with modern TLS.
  • Passwords are hashed with bcrypt; we never store them in plain text.
  • Short-lived access tokens with secure, HTTP-only refresh cookies; sessions can be ended by changing your password.
  • Email verification and one-time passwords for sensitive actions.
  • Rate limiting and abuse detection on sign-in, sign-up and public endpoints.
  • Payments are handled entirely by Razorpay (PCI DSS compliant); we never see card or bank details.
  • Uploaded files are type- and size-checked before storage.
  • Admin access is restricted to authorised staff and logged.
  • Regular encrypted backups and dependency updates.

2. Keeping your account safe

  • Use a unique, strong password or sign in with Google.
  • Never share one-time passwords. Selectvia staff will never ask for them.
  • If you notice suspicious activity, change your password and email security@selectvia.com.

3. Reporting a vulnerability

Email security@selectvia.com with a description, steps to reproduce, affected URLs and the impact you believe it has. Please don't include other users' personal data beyond what's needed to demonstrate the issue.

4. Rules for researchers

  • Only test against your own accounts and catalogues.
  • Don't access, modify or delete other users' data; stop and report as soon as you encounter it.
  • No denial-of-service, spam, social engineering of staff or users, or physical attacks.
  • Don't run automated scanners that generate heavy traffic.
  • Give us reasonable time to fix the issue before disclosing it publicly.

5. Our commitment

  • Acknowledge your report within 3 working days and keep you updated.
  • Fix confirmed issues as quickly as their severity requires.
  • Credit you publicly if you wish, once the issue is fixed.
  • Not pursue legal action for good-faith research that follows this policy.

6. Out of scope

  • Reports from automated tools without a demonstrated impact.
  • Missing security headers or best-practice suggestions without an exploit.
  • Clickjacking on pages with no sensitive actions, self-XSS, and logout CSRF.
  • Vulnerabilities in third-party services (report those to the vendor).

7. Security incidents

If a personal data breach affects you, we will notify you and the Data Protection Board of India as required by the DPDP Act, 2023, and report cyber security incidents to CERT-In within the time it requires.