Security
Security & Responsible Disclosure
Last updated: 2026-07-18
We take security seriously and welcome reports from researchers, customers, and the wider community. This page explains how to report a vulnerability, what to expect from us, and the rules of engagement that keep everyone protected.
How to report
Email security@finnilai.com with:
- A description of the issue and its potential impact.
- Steps to reproduce — enough for us to verify from a fresh test account. A short screen recording or a minimal PoC script is ideal.
- Your name or handle (for the hall of fame, if you want credit) and a public key if you’d like to encrypt follow-ups.
The machine-readable pointer for this policy is at /.well-known/security.txt.
Our commitment to you
- Acknowledgement within 24 hours of your initial email (business days).
- Triage verdict within 3 business days — we’ll tell you whether we’ve reproduced it and the severity we assigned.
- Fix timelines based on severity:
- Critical: patch within 24 hours.
- High: patch within 7 days.
- Medium: patch within 30 days.
- Low: next scheduled release.
- Coordinated disclosure. We ask for a 90-day embargo from initial report — extendable if you need more time to prepare a write-up. Public credit in the hall of fame below (opt-in).
- No paid bounty at this stage — we’re a small team without a formal bounty budget yet. We offer swag, public credit, and free FinNilai Business subscriptions for the researcher of a valid, previously unknown finding.
Safe harbour
If you make a good-faith effort to comply with this policy during your security research, we will:
- Consider your research to be authorised and will not pursue civil action or file a complaint with law enforcement.
- Work with you to understand and resolve the issue quickly.
- Recognise your contribution publicly if you were the first to report the issue.
“Good-faith effort” means: you tested only against accounts you own or have explicit permission to test; you did not access, modify, or delete other users’ data beyond the minimum needed to demonstrate the vulnerability; you did not degrade the service for other users; and you gave us a reasonable chance to fix the issue before disclosure.
Scope
In scope:
finnilai.comand all subdomains we operate- The FinNilai web application
- FinNilai’s public API (
/api/v1/*) - The FinNilai mobile web experience
Out of scope (please don’t submit these — they’ll be closed as informational):
- Reports from automated scanners without a working PoC
- Rate-limiting or brute-force issues on non-authentication endpoints
- Missing security headers on non-sensitive endpoints
- Clickjacking on pages without sensitive state changes
- Self-XSS or issues requiring the victim to paste code into DevTools
- Attacks requiring physical access, a rooted / jailbroken device, or root-level malware
- Denial-of-service via load generation (do not attempt this — it hurts other customers)
- Third-party services we integrate with (Razorpay, Supabase, Vercel, Meta, Resend, Sentry) — report those to the respective vendor
- Social engineering of our staff, customers, or vendors
- Findings in dependencies that are already CVE-tracked
Please don’t
- Access, modify, download, or delete data belonging to other FinNilai customers.
- Run automated scans that generate significant traffic.
- Attempt to phish, social-engineer, or otherwise target FinNilai staff or customers.
- Publicly disclose the vulnerability before we’ve had a chance to fix it and confirm coordinated disclosure.
Hall of fame
No reports yet. First valid finding gets the top spot and a year of FinNilai Business on us.
Contact
Security team: security@finnilai.com. For non-security questions about how we protect data, see /trust or /privacy.