1. How to report
Email security@tipoffly.com. Write in English. Please don't post the problem in public, in app store reviews or on social media until we've fixed it and agreed a date with you.
Our contact details are also published in machine-readable form at /.well-known/security.txt, following RFC 9116.
2. What to include
- What the problem is and what an attacker could do with it
- Where it is: the web address, the app screen or the API call
- Steps to reproduce it, with the app version and phone model if it's in the app
- Screenshots, a short video or a proof-of-concept, if you have one
- How you'd like to be credited, or that you'd rather stay anonymous
Never send us real personal data you came across, such as someone else's phone number or alerts. Describe it instead, and delete any copy you hold.
3. What we promise
- We'll confirm we got your report within [3 working days]
- We'll tell you whether we can reproduce it and how serious we think it is within [10 working days]
- We'll keep you updated while we fix it, and tell you when it's fixed
- We'll credit you on this page when the fix is out, if you'd like that
We aim to fix serious problems within [90 days] and will agree any public disclosure date with you. If a problem puts people's data at risk, we'll also meet our duties under the Digital Personal Data Protection Act, 2023 and report to CERT-In where the law requires it.
We don't run a paid bug bounty at the moment. [Owner to confirm.]
4. What's in scope
- The website at tipoffly.com, including sign-in, plans, checkout and invoices
- The TipOffly server that the apps and website talk to
- The TipOffly Android and iPhone apps, once they're published
Out of scope: the payment pages run by Razorpay, Google Play, the App Store, our hosting and SMS providers, and any other company's service. Please report problems in those to the company that runs them.
We generally don't treat these as security problems on their own: missing headers with no real impact, clickjacking on pages with nothing to click, self-XSS, reports from automated scanners with no proof of impact, rate limits on non-sensitive pages, and the version numbers of software we use.
5. Rules for testing
- Use only accounts you own, or that you made for testing
- Never look at, change or delete other people's data. If you reach some by accident, stop and tell us
- No denial-of-service, spam, brute force or heavy automated scanning
- No phishing, social engineering or physical attacks on our team, users or offices
- Don't keep a foothold: no backdoors, and no moving deeper once you've proved the problem
- Give us a fair chance to fix it before telling anyone else
6. Safe harbour
If you follow this page in good faith, we won't take legal action against you or ask the police to, and we'll consider your research authorised as far as we're able to. If someone else complains about your research, we'll make clear that you acted under this policy. This doesn't cover anything that breaks the law in a way we can't waive, or harms our users. [Lawyer to review.]
7. Not a security issue?
- Got a scam call or message pretending to be TipOffly? Forward it to support@tipoffly.com
- Lost money to fraud? Call 1930 or report at cybercrime.gov.in straight away
- Can't sign in, or think someone else is in your account? Write to support@tipoffly.com
- A question about your personal data? See the Privacy Policy or write to privacy@tipoffly.com