Reporting a vulnerability
If you believe you have found a security vulnerability in ARCORA or any Truffaire Systems product, please report it to us at security@truffaire.in. We take all reports seriously and will respond within 3 business days.
What to include
- ·A description of the vulnerability and where it was found
- ·Steps to reproduce, or a proof-of-concept (no live exploitation please)
- ·The potential impact you believe the issue could have
- ·Your contact details if you would like to be credited
Our commitments
- ·We will acknowledge your report within 3 business days
- ·We will keep you informed as we investigate and fix the issue
- ·We will not take legal action against researchers acting in good faith
- ·We will credit you publicly if you wish, once the issue is resolved
Scope
This policy applies to arcora.truffaire.in and all subdomains operated by Truffaire Systems. It does not cover third-party services (Razorpay, Clerk, Convex, Vercel) which have their own disclosure programmes.
Out of scope
- ·Denial-of-service attacks
- ·Social engineering or phishing of Truffaire staff
- ·Vulnerabilities in third-party libraries (report directly to the library maintainers)
- ·Missing security headers on low-sensitivity pages