Legal
Security & Responsible Disclosure Policy
Last updated
In short
- Data is encrypted in transit, passwords are hashed, and staff access is limited.
- Report vulnerabilities to security@selectvia.com; we respond within 3 working days.
- Good-faith research under this policy won't lead to legal action from us.
This summary is for convenience; the full text below is what applies.
1. How we protect data
- All traffic is served over HTTPS with modern TLS.
- Passwords are hashed with bcrypt; we never store them in plain text.
- Short-lived access tokens with secure, HTTP-only refresh cookies; sessions can be ended by changing your password.
- Email verification and one-time passwords for sensitive actions.
- Rate limiting and abuse detection on sign-in, sign-up and public endpoints.
- Payments are handled entirely by Razorpay (PCI DSS compliant); we never see card or bank details.
- Uploaded files are type- and size-checked before storage.
- Admin access is restricted to authorised staff and logged.
- Regular encrypted backups and dependency updates.
2. Keeping your account safe
- Use a unique, strong password or sign in with Google.
- Never share one-time passwords. Selectvia staff will never ask for them.
- If you notice suspicious activity, change your password and email security@selectvia.com.
3. Reporting a vulnerability
Email security@selectvia.com with a description, steps to reproduce, affected URLs and the impact you believe it has. Please don't include other users' personal data beyond what's needed to demonstrate the issue.
4. Rules for researchers
- Only test against your own accounts and catalogues.
- Don't access, modify or delete other users' data; stop and report as soon as you encounter it.
- No denial-of-service, spam, social engineering of staff or users, or physical attacks.
- Don't run automated scanners that generate heavy traffic.
- Give us reasonable time to fix the issue before disclosing it publicly.
5. Our commitment
- Acknowledge your report within 3 working days and keep you updated.
- Fix confirmed issues as quickly as their severity requires.
- Credit you publicly if you wish, once the issue is fixed.
- Not pursue legal action for good-faith research that follows this policy.
6. Out of scope
- Reports from automated tools without a demonstrated impact.
- Missing security headers or best-practice suggestions without an exploit.
- Clickjacking on pages with no sensitive actions, self-XSS, and logout CSRF.
- Vulnerabilities in third-party services (report those to the vendor).
7. Security incidents
If a personal data breach affects you, we will notify you and the Data Protection Board of India as required by the DPDP Act, 2023, and report cyber security incidents to CERT-In within the time it requires.