Skip to content
attpro
Book a demo
All legal documents

Legal

Responsible disclosure

If you find a security issue in this website or the attpro platform, tell us privately. We acknowledge within 48 hours, keep you informed through the fix, and do not pursue good-faith research conducted within these rules.

Effective
Last updated
Sections
7 numbered sections, each with its own anchor

Drafted as an honest statement of how we operate; formal counsel review is pending and this notice remains until it is complete.

On this page
01

Scope

In scope:

  • this website (https://attpro.in) and its lead endpoint;
  • the attpro platform at https://crm.attpro.collbox.in and its APIs;
  • the borrower self-service portal and payment-link pages;
  • the field officer mobile application.

Out of scope: third-party services we integrate with (telephony, messaging, payment gateways, cloud providers), which have their own programmes; social engineering of our staff or customers; physical attacks; denial of service.

02

How to report

Write to info@attpro.in with “Security” in the subject. Include the affected URL or endpoint, steps to reproduce, the impact as you understand it, and any proof-of-concept. If you need to send sensitive material, ask for an encryption key first and we will provide one.

03

What we ask of you

  • Test only against systems you are authorised to use, and only with test accounts you own.
  • Do not access, modify or exfiltrate another party’s data; if you encounter it, stop and report.
  • Do not degrade service for others; no automated scanning at volume, no denial of service.
  • Give us a reasonable window - 90 days by default - before any public disclosure.
  • Do not demand payment as a condition of reporting.
04

What we commit to

  • Acknowledgement within 48 hours.
  • An initial assessment and severity within 5 working days.
  • Progress updates until the issue is resolved, and notice when it is.
  • Credit on this page, if you want it, once the fix has shipped.
05

Safe harbour

Research conducted in good faith and within these rules is authorised. We will not pursue civil or criminal action against you for it, and if a third party does, we will make it known that your actions were authorised. This safe harbour does not extend to actions outside the rules above or that breach the law.

06

How we rate severity

We use CVSS v3.1 as a starting point and adjust for real impact on borrower data, tenant isolation and payment integrity. Issues that could expose one lender’s book to another, or alter a payment or a recorded promise, are treated as critical regardless of score.

07

Acknowledgements

Researchers who have helped us and asked to be named will be listed here. There are none yet; we would rather say so than invent a list.

Questions about this document

Write to info@attpro.in with the document name in the subject. We reply within one working day.

Need a copy for your file

Print this page, or ask for a dated PDF and the change history through the Trust Center.