Legal
Responsible disclosure
If you find a security issue in this website or the attpro platform, tell us privately. We acknowledge within 48 hours, keep you informed through the fix, and do not pursue good-faith research conducted within these rules.
- 7 numbered sections, each with its own anchor
Drafted as an honest statement of how we operate; formal counsel review is pending and this notice remains until it is complete.
On this page
01Scope
In scope:
- this website (https://attpro.in) and its lead endpoint;
- the attpro platform at https://crm.attpro.collbox.in and its APIs;
- the borrower self-service portal and payment-link pages;
- the field officer mobile application.
Out of scope: third-party services we integrate with (telephony, messaging, payment gateways, cloud providers), which have their own programmes; social engineering of our staff or customers; physical attacks; denial of service.
02How to report
Write to info@attpro.in with “Security” in the subject. Include the affected URL or endpoint, steps to reproduce, the impact as you understand it, and any proof-of-concept. If you need to send sensitive material, ask for an encryption key first and we will provide one.
03What we ask of you
- Test only against systems you are authorised to use, and only with test accounts you own.
- Do not access, modify or exfiltrate another party’s data; if you encounter it, stop and report.
- Do not degrade service for others; no automated scanning at volume, no denial of service.
- Give us a reasonable window - 90 days by default - before any public disclosure.
- Do not demand payment as a condition of reporting.
04What we commit to
- Acknowledgement within 48 hours.
- An initial assessment and severity within 5 working days.
- Progress updates until the issue is resolved, and notice when it is.
- Credit on this page, if you want it, once the fix has shipped.
05Safe harbour
Research conducted in good faith and within these rules is authorised. We will not pursue civil or criminal action against you for it, and if a third party does, we will make it known that your actions were authorised. This safe harbour does not extend to actions outside the rules above or that breach the law.
06How we rate severity
We use CVSS v3.1 as a starting point and adjust for real impact on borrower data, tenant isolation and payment integrity. Issues that could expose one lender’s book to another, or alter a payment or a recorded promise, are treated as critical regardless of score.
07Acknowledgements
Researchers who have helped us and asked to be named will be listed here. There are none yet; we would rather say so than invent a list.
Questions about this document
Write to info@attpro.in with the document name in the subject. We reply within one working day.
Need a copy for your file
Print this page, or ask for a dated PDF and the change history through the Trust Center.