Security & Responsible Disclosure
Published: September 2026 • Security Team: VANIKARA INTELLIGENCE PRIVATE LIMITED
1. Our Security Philosophy
Security is not an afterthought at VANIKARA; it is an architectural baseline. We enforce strict database row-level security, environment variable hygiene, server-side data sanitization, cryptographic session tokens, and hardened HTTP response headers (CSP, HSTS, X-Frame-Options) across our web apps.
2. Responsible Vulnerability Disclosure Program
We welcome responsible security researchers who assist us in maintaining the integrity of our software. If you identify a potential security vulnerability in our public endpoints, applications, or systems, please notify us immediately.
3. Reporting Guidelines
- Email technical findings directly to: support@vanikara.com or contact@vanikara.com.
- Include reproducible steps, target URI, payload samples, and potential business impact.
- Allow our engineering team reasonable time to investigate and remediate the issue prior to public disclosure.
- Do NOT access, alter, delete, or exfiltrate private customer or merchant data.
- Do NOT execute automated Denial of Service (DDoS) attacks, brute-force spamming, or physical social engineering.
4. Our Commitment
For valid vulnerability submissions that follow these responsible disclosure principles, we commit to acknowledging reports within 48 business hours, keeping you updated on remediation progress, and recognizing your contribution.
