Reporting a vulnerability
If you believe you have found a security vulnerability in Alvida, please report it to us privately before disclosing it publicly. We take all reports seriously and will respond promptly.
Email your report to security@alvida.in. Include a clear description of the issue, the steps to reproduce it, and the potential impact. We will acknowledge your email within 2 business days.
What we ask of you
- Give us reasonable time to investigate and fix the issue before any public disclosure.
- Do not access, modify, or delete data that does not belong to you.
- Do not perform denial-of-service attacks or disrupt the service for other users.
- Do not use automated scanners against production infrastructure without prior written permission.
What you can expect from us
- We will not take legal action against researchers who report in good faith under this policy.
- We will keep you informed as we investigate and resolve the issue.
- We will credit you in our acknowledgements if you wish (just let us know).
- We will aim to resolve critical vulnerabilities within 7 days and others within 30 days.
In scope
- The Alvida web application at alvida.in
- Authentication and session management
- Message confidentiality and access controls
- Check-in and delivery logic
- API endpoints
Out of scope
- Social engineering or phishing attacks against Alvida staff or users
- Denial-of-service attacks
- Vulnerabilities in third-party services we rely on (Supabase, Vercel, Resend) — report those directly to the respective vendors
- Issues requiring physical access to a user's device