Back

Responsible reporting

Found a security issue?
Report it safely.

Please stop before accessing another person's or institution's data. Send enough information for us to reproduce the issue without expanding the impact.

Email security@smarthisaab.in

Use a clear subject such as “Security report: [short issue summary]”. For a personal-data incident, also copy privacy@smarthisaab.in.

Include in the report

  • The affected URL, role and workflow
  • Steps that reproduce the behaviour using only accounts and data you are authorised to access
  • The security impact you believe could occur
  • Relevant request or response details with tokens, cookies, passwords and personal data redacted
  • A safe way to contact you for clarification

Keep the test safe

  • Do not view, alter, download or retain another tenant's information
  • Do not disrupt availability, send bulk messages, run denial-of-service tests or automate high-volume requests
  • Do not use social engineering, phishing, physical access attempts or attacks against providers
  • Do not publish the issue before we have had a reasonable opportunity to investigate and address it
No public bug-bounty programme is currently offered. Reporting an issue does not create a promise of payment or reward. We will still review good-faith reports and communicate about validated issues where practical.

Product help is separate

Use Support for sign-in, setup and ordinary product problems. See Trust for the current security and infrastructure boundaries we publicly describe.