Security & Responsible Disclosure Policy
This policy outlines our security practices and provides guidelines for security researchers to report vulnerabilities responsibly.
1. Platform Security Measures
We use SSL encryption for all network traffic, secure JWTs for session management, and encrypt sensitive KYC details. Public media is stored securely on Cloudflare R2 CDN.
2. Responsible Disclosure Guidelines
If you discover a vulnerability, please report it to admin@breakingstocks.in before disclosing it publicly. Reports should include detailed replication steps and a proof of concept.
3. Disclosure Timelines & Safe Harbor
We will acknowledge reports within 3 business days and aim to patch verified issues within 90 days. We agree not to pursue legal action against researchers who comply with these guidelines.
4. Reward Eligibility
We do not currently offer cash rewards for vulnerability disclosures, but we will credit researchers in our Security Hall of Fame for verified reports.