Responsible disclosure
Bug Bounty & Security Reports
Help protect SIRF users by reporting security issues privately, with the minimum evidence needed to reproduce them.
Report a vulnerability
Email our existing contact address with the subject “Security report – SIRF”. Include the affected URL, a brief impact explanation, reproduction steps using your own test accounts, and redacted screenshots if useful.
Send private security reportDo not include passwords, OTPs, API secrets, identity documents or other users’ personal information. Email is not a secure document-upload channel.
Scope and safe testing
This policy covers SIRF-owned application functionality on https://sirf.one only. Keep testing low-volume, non-destructive and limited to accounts and records you own. Ask privately before any test outside these boundaries.
- Report authentication, authorization, private-data exposure, injection and other reproducible security defects.
- Do not access, enumerate, download, modify or delete other users’ data. If private data appears unexpectedly, stop immediately and report only minimal redacted evidence.
- No denial-of-service, load testing, brute force, spam, social engineering, malware, payment abuse or disruption of daily publishing.
- Third-party infrastructure and services—including Google/Firebase, Razorpay, Hostinger, linked stores and other websites on our server—are not authorized testing targets.
- Do not publish exploit details or personal data. Coordinate disclosure privately after a fix has been reviewed.
This policy does not grant access to another person’s account, waive third-party rights or provide blanket legal immunity.
Review and rewards
Reports are assessed for reproducibility, impact, scope and duplicates. Provide a reply address so we can request clarification and coordinate a fix. Response times are not guaranteed.
No paid bounty schedule or reward budget is currently committed. A report does not create an entitlement to payment. Any future reward terms will be published explicitly before they apply.
General usability bugs, feature requests and account-support questions belong with ordinary support. Public client-side code or a public configuration identifier alone is not evidence of a vulnerability; explain a demonstrable security impact.