Security
Vulnerability Disclosure Policy
How to report a security issue in Mangalyam, what is in scope, and what you can expect from us in return. We welcome good-faith security research.
Effective: 2026-08-02·Last updated: 2026-08-02·Version: v1.0
Owner: Mangalyam Security·Status: active
Scope: All Mangalyam-operated web surfaces, APIs, and infrastructure at mangalyam.io.
Policy key: vulnerability-disclosure·Audience: all·Next review: 2027-08-02
1) How to report
Email security@mangalyam.io with a clear description of the issue, the affected URL or endpoint, and step-by-step reproduction details. A proof-of-concept, screenshots, or a short screen recording help us triage faster.
A machine-readable pointer to this policy is published at /.well-known/security.txt (RFC 9116).
Please report in English. Do not disclose the issue publicly until we have had a reasonable chance to investigate and remediate.
2) Scope
In scope: the mangalyam.io web application and its public APIs, authentication and session handling, tenant/data isolation (cross-tenant access), payment and payout flows, and file upload/storage paths.
Out of scope: findings that require a rooted/jailbroken device or physical access; social engineering of our staff, partners, or users; denial-of-service and volumetric/load testing; spam or content issues; reports from automated scanners without a demonstrated, exploitable impact; and issues in third-party services we do not operate (report those to the respective vendor).
3) Good-faith safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.
Good faith means: only interact with accounts you own or have explicit permission to test; do not access, modify, or destroy other users’ data; do not degrade our services; and stop and report as soon as you have demonstrated a vulnerability.
4) What to expect from us
We aim to acknowledge your report within 3 business days and to provide an initial assessment within 10 business days. Timelines may vary with severity and complexity; we will keep you informed.
We do not currently operate a paid bug-bounty program — there is no monetary reward at this time. We are grateful for responsible disclosure and are happy to credit reporters who wish to be acknowledged once an issue is resolved.
5) Honest security posture
Mangalyam is an early-stage platform. We are not currently SOC 2 or ISO 27001 certified and we do not claim any certification we do not hold.
We enforce tenant isolation with Postgres row-level security, keep secrets out of client code, run automated dependency, secret, and static-analysis scans in CI, and are continuously hardening. If you find a gap, telling us is the fastest way to close it.
Need a policy clarification? Email hello@mangalyam.io with your account email, booking reference, and policy question.