Security Policy

Last updated: August 2026

Reporting a vulnerability

If you believe you have found a security vulnerability in Alvida, please report it to us privately before disclosing it publicly. We take all reports seriously and will respond promptly.

Email your report to security@alvida.in. Include a clear description of the issue, the steps to reproduce it, and the potential impact. We will acknowledge your email within 2 business days.

What we ask of you

  • Give us reasonable time to investigate and fix the issue before any public disclosure.
  • Do not access, modify, or delete data that does not belong to you.
  • Do not perform denial-of-service attacks or disrupt the service for other users.
  • Do not use automated scanners against production infrastructure without prior written permission.

What you can expect from us

  • We will not take legal action against researchers who report in good faith under this policy.
  • We will keep you informed as we investigate and resolve the issue.
  • We will credit you in our acknowledgements if you wish (just let us know).
  • We will aim to resolve critical vulnerabilities within 7 days and others within 30 days.

In scope

  • The Alvida web application at alvida.in
  • Authentication and session management
  • Message confidentiality and access controls
  • Check-in and delivery logic
  • API endpoints

Out of scope

  • Social engineering or phishing attacks against Alvida staff or users
  • Denial-of-service attacks
  • Vulnerabilities in third-party services we rely on (Supabase, Vercel, Resend) — report those directly to the respective vendors
  • Issues requiring physical access to a user's device

Contact

security@alvida.in