BackFound a security issue?
Responsible reporting
Found a security issue?
Report it safely.
Please stop before accessing another person's or institution's data. Send enough information for us to reproduce the issue without expanding the impact.
Email security@smarthisaab.in
Use a clear subject such as “Security report: [short issue summary]”. For a personal-data incident, also copy privacy@smarthisaab.in.
Include in the report
- The affected URL, role and workflow
- Steps that reproduce the behaviour using only accounts and data you are authorised to access
- The security impact you believe could occur
- Relevant request or response details with tokens, cookies, passwords and personal data redacted
- A safe way to contact you for clarification
Keep the test safe
- Do not view, alter, download or retain another tenant's information
- Do not disrupt availability, send bulk messages, run denial-of-service tests or automate high-volume requests
- Do not use social engineering, phishing, physical access attempts or attacks against providers
- Do not publish the issue before we have had a reasonable opportunity to investigate and address it
No public bug-bounty programme is currently offered. Reporting an issue does not create a promise of payment or reward. We will still review good-faith reports and communicate about validated issues where practical.
Product help is separate
Use Support for sign-in, setup and ordinary product problems. See Trust for the current security and infrastructure boundaries we publicly describe.