Legal

Responsible Disclosure

How security researchers should report vulnerabilities to Khodi Mart — security@khodi.in.

Last updated: July 2026

1. We welcome reports

If you discover a security vulnerability in Khodi Mart (web apps, APIs, auth, or integration token handling), please report it privately so we can fix it before public disclosure. Marketplace partner trust depends on responsible handling of issues.

2. How to report

  1. Email security@khodi.in with subject “Vulnerability report”.
  2. Include: affected URL/endpoint, account role (if any), clear steps to reproduce, expected vs actual behaviour, and impact assessment.
  3. Prefer redacted PoCs — do not include live production tokens, passwords, or customer PII.
  4. Do not access other users’ data beyond what is needed to demonstrate the issue.
  5. Allow us a reasonable remediation window before public disclosure (typically 90 days for non-critical issues; faster coordination for critical).

3. Safe harbour

We will not pursue legal action against researchers who make a good-faith effort to follow this policy, avoid privacy violations and service disruption, and report promptly. This does not authorise attacks on third-party marketplace, carrier, or payment systems, or exploitation of other customers’ accounts.

4. Out of scope (examples)

  • Social engineering of our staff or customers.
  • Denial-of-service / volumetric attacks.
  • Reports from automated scanners without a demonstrated impact.
  • Issues in third-party marketplace or carrier platforms.
  • Missing security headers without a practical exploit path.
  • Self-XSS that requires the victim to paste code into their own console.

5. Recognition

At our discretion we may thank researchers in a private note or future hall-of-fame. We do not currently run a public bug bounty with guaranteed payouts; Enterprise partners may negotiate separate research programmes.

6. Contact

Primary: security@khodi.in. Fallback: support@khodimart.com with subject “Security”. Also see Security Policy and Security Center.

Also see Trust Center, Privacy, Terms, Security, Compliance, Cookies, DPA, Disclosure, and Help.