Responsible Disclosure
We value the security of our platform and the privacy of our users. If you believe you’ve found a security vulnerability in App Deals, we appreciate your help in responsibly disclosing it to us.
Our Commitment
We are committed to addressing security issues responsibly and in a timely manner. If you follow the guidelines below, we will not pursue or support any legal action related to your research.
Scope
- appdeals.in web application and its first‑party APIs.
- Publicly reachable endpoints under our domain(s).
- Mobile app API endpoints used by the official App Deals app.
Out of Scope
- Rate‑limiting/brute force without practical impact.
- Clickjacking on non‑sensitive pages.
- Best‑practice recommendations without a concrete vulnerability.
- Third‑party services and providers not owned by us.
- Denial of Service (DoS), spam, or social engineering.
Safe Harbor
We pledge not to initiate legal action for testing that adheres to these guidelines. Make a good‑faith effort to avoid privacy violations, data destruction, and service disruption.
Guidelines
- Only test against accounts and data you own or have explicit permission to use.
- Avoid accessing or modifying data that does not belong to you.
- Do not degrade our services or impact other users.
- Give us reasonable time to remediate before public disclosure.
How to Report
Please include the following details to help us triage efficiently:
- Vulnerability description and potential impact.
- Step‑by‑step reproduction instructions, affected endpoint/URL.
- Any proof‑of‑concept (PoC), screenshots, or videos.
- Suggested remediation, if available.
Recognition / Bug Bounty
We currently offer recognition and, for qualifying findings based on severity and impact, discretionary rewards. Rewards and recognition are evaluated case‑by‑case at our sole discretion.
Disclosure Policy
Please allow us sufficient time to investigate and remediate before you disclose publicly. We’ll keep you informed of progress and notify you when it’s appropriate to disclose.