FinNilai
TrustSecurityPrivacyTermsRefunds

Security

Security & Responsible Disclosure

Last updated: 2026-07-18

We take security seriously and welcome reports from researchers, customers, and the wider community. This page explains how to report a vulnerability, what to expect from us, and the rules of engagement that keep everyone protected.

How to report

Email security@finnilai.com with:

  • A description of the issue and its potential impact.
  • Steps to reproduce — enough for us to verify from a fresh test account. A short screen recording or a minimal PoC script is ideal.
  • Your name or handle (for the hall of fame, if you want credit) and a public key if you’d like to encrypt follow-ups.

The machine-readable pointer for this policy is at /.well-known/security.txt.

Our commitment to you

  • Acknowledgement within 24 hours of your initial email (business days).
  • Triage verdict within 3 business days — we’ll tell you whether we’ve reproduced it and the severity we assigned.
  • Fix timelines based on severity:
    • Critical: patch within 24 hours.
    • High: patch within 7 days.
    • Medium: patch within 30 days.
    • Low: next scheduled release.
  • Coordinated disclosure. We ask for a 90-day embargo from initial report — extendable if you need more time to prepare a write-up. Public credit in the hall of fame below (opt-in).
  • No paid bounty at this stage — we’re a small team without a formal bounty budget yet. We offer swag, public credit, and free FinNilai Business subscriptions for the researcher of a valid, previously unknown finding.

Safe harbour

If you make a good-faith effort to comply with this policy during your security research, we will:

  • Consider your research to be authorised and will not pursue civil action or file a complaint with law enforcement.
  • Work with you to understand and resolve the issue quickly.
  • Recognise your contribution publicly if you were the first to report the issue.

“Good-faith effort” means: you tested only against accounts you own or have explicit permission to test; you did not access, modify, or delete other users’ data beyond the minimum needed to demonstrate the vulnerability; you did not degrade the service for other users; and you gave us a reasonable chance to fix the issue before disclosure.

Scope

In scope:

  • finnilai.com and all subdomains we operate
  • The FinNilai web application
  • FinNilai’s public API (/api/v1/*)
  • The FinNilai mobile web experience

Out of scope (please don’t submit these — they’ll be closed as informational):

  • Reports from automated scanners without a working PoC
  • Rate-limiting or brute-force issues on non-authentication endpoints
  • Missing security headers on non-sensitive endpoints
  • Clickjacking on pages without sensitive state changes
  • Self-XSS or issues requiring the victim to paste code into DevTools
  • Attacks requiring physical access, a rooted / jailbroken device, or root-level malware
  • Denial-of-service via load generation (do not attempt this — it hurts other customers)
  • Third-party services we integrate with (Razorpay, Supabase, Vercel, Meta, Resend, Sentry) — report those to the respective vendor
  • Social engineering of our staff, customers, or vendors
  • Findings in dependencies that are already CVE-tracked

Please don’t

  • Access, modify, download, or delete data belonging to other FinNilai customers.
  • Run automated scans that generate significant traffic.
  • Attempt to phish, social-engineer, or otherwise target FinNilai staff or customers.
  • Publicly disclose the vulnerability before we’ve had a chance to fix it and confirm coordinated disclosure.

Hall of fame

No reports yet. First valid finding gets the top spot and a year of FinNilai Business on us.

Contact

Security team: security@finnilai.com. For non-security questions about how we protect data, see /trust or /privacy.

For questions about any clause on this page, contact our grievance officer at contact@finnilai.com.