Security Policy

Responsible Disclosure

Effective: 7 April 2026 Scope: For all Tradesala products Version: 1.0

At Tradesala Technologies Pvt Ltd, we build tools used by thousands of Indian sellers every day. Security is not an afterthought — it is a core commitment. We welcome responsible security research and are grateful to researchers who help us keep our platform and our sellers safe.

This policy explains what we consider to be in scope, how to report a vulnerability, what you can expect from us, and what we ask of you in return.

Scope

✓ In Scope
tools.tradesala.store and all subdomains
tradesala.com and all subdomains
Tradesala mobile apps (Android / iOS)
Authentication and session management
API endpoints and data exposure
Cross-site scripting (XSS)
SQL injection and server-side vulnerabilities
Seller account data, business details & financials
Customer / buyer personal data & order information
Any data processed, stored, or transmitted by Tradesala
✕ Out of Scope
Denial of service (DoS / DDoS) attacks
Physical security of our offices
Social engineering of Tradesala staff
Third-party services we do not control
Automated scanner output without PoC
Self-XSS with no real-world impact
Rate limiting on non-sensitive endpoints
Missing security headers (low severity)

Data We Are Committed to Protecting

Tradesala handles sensitive data on behalf of thousands of Indian sellers and their customers. Any vulnerability that touches the following categories is treated with the highest priority and must be reported immediately to security@tradesala.com.

Seller Data
Seller business details — company name, address, GSTIN, PAN, bank account information
Seller login credentials, session tokens, and account access
Sales data, order history, revenue figures, and financial records
Inventory data, product catalogues, pricing, and supplier information
Customer / Buyer Data
Buyer personal details — full name, phone number, email address
Delivery addresses and pincode data
Order details, payment mode (COD / prepaid), and transaction history
Any personally identifiable information (PII) as defined under the DPDP Act, 2023
Platform & Operational Data
Internal system configurations, infrastructure details, or API keys
Tradesala employee credentials or internal communication systems
Any data processed, stored, or transmitted by Tradesala on behalf of any party

If you accidentally access any of the above data while conducting research, stop immediately, do not copy or retain it, and disclose this in your report. We will not penalise accidental access reported in good faith.

How to Report

Please send all vulnerability reports to security@tradesala.com with the subject line Security Vulnerability Report. This inbox is monitored by our engineering team, not our legal team — your report reaches the right people immediately. We prefer reports in English, Tamil, or Hindi.

Include in your report
1
Vulnerability description
Type of issue (e.g. XSS, IDOR, SQL injection), affected URL or component, and its potential impact on sellers or Tradesala.
2
Reproduction steps
Clear, numbered steps to reproduce the issue. Include the HTTP request/response if relevant.
3
Proof of concept
Screenshots, screen recordings, or a minimal PoC. Do not access, modify, or delete real user data beyond what is needed to demonstrate the issue.
4
Your contact details
Name (or handle) and a reply email. We'll use this to send you updates and acknowledgement.

Response Timelines

We take every report seriously. Our committed response timelines by severity are:

Severity Examples Initial Response Target Resolution
Critical RCE, auth bypass, mass data leak Within 48 hours 15 days or more
High IDOR, stored XSS, privilege escalation Within 72 hours 15 days or more
Medium Reflected XSS, CSRF, info disclosure Within 72 hours 30 days or more
Low Best-practice gaps, low-impact issues Within 5 days 90 days or more

We will keep you updated if a fix requires more time than the target above, and will not go silent on valid reports.

Our Commitments to You

We will not pursue legal action
Researchers who follow this policy and act in good faith will not face legal action from Tradesala under India's IT Act or any other law.
We will acknowledge every valid report
Valid reports will be acknowledged by name or handle (your choice) in our security acknowledgements page once the fix is shipped.
We will keep you in the loop
We will share our assessment of the issue, our fix timeline, and notify you when the vulnerability has been resolved.
We will work with you on disclosure timing
We follow coordinated disclosure. We ask for a reasonable embargo period (typically 90 days for non-critical issues) before public disclosure.

What We Ask of You

To be covered under this policy, please act in good faith and follow these guidelines:

Do not access, copy, download, modify, or delete data belonging to sellers, customers, or Tradesala beyond the absolute minimum needed to demonstrate the vulnerability.
Do not perform denial-of-service attacks, spam, or any action that degrades the experience for our sellers or their customers.
Do not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it.
Do not use automated scanners against our production systems without prior written permission.
Do not conduct research on seller or customer accounts that do not belong to you. Create your own test account for testing.
If you inadvertently access seller financials, Customer Personally Identifiable Information (PII), or any other sensitive data, disclose this immediately in your report and do not retain copies.

Legal & Jurisdiction

Tradesala Technologies Pvt Ltd is incorporated in India (CIN: U74999TN2020PTC137626), registered in Chennai, Tamil Nadu. This policy is governed by the laws of India, including the Information Technology Act, 2000 and its amendments.

Security researchers who act in good faith and within the boundaries of this policy are explicitly authorised to conduct the research described above on our in-scope systems. Tradesala will not initiate legal proceedings against researchers who comply with this policy.

Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu, India.

Zero Tolerance for Malicious Activity

This policy exists to support responsible, good-faith security research. It is not a licence for malicious conduct of any kind.

Any individual, entity, or group that intentionally and maliciously targets Tradesala Technologies Pvt Ltd, its products, platforms, sellers, customers, or associated services — including but not limited to acts of hacking, unauthorised access, theft of seller or customer data, financial data exfiltration, system tampering, service disruption, brand tarnishing, reputation damage, defacement, or coordinated attacks — will be subject to the full force of applicable law.

Applicable Laws — India
Information Technology Act, 2000 — Sections 43, 66, 66B, 66C, 66D, 66F — covering unauthorised access, data theft, identity fraud, cyberterrorism, and computer damage. Punishable by imprisonment of up to 7 years and/or fine.
Indian Penal Code (IPC) / Bharatiya Nyaya Sanhita, 2023 — Sections covering criminal breach of trust, cheating, forgery, and conspiracy applicable to digital fraud and theft.
Trade Marks Act, 1999 — The Tradesala brand, logo, and associated marks are protected intellectual property. We permit the use of our logos for promotional social media and advertising, provided the use strictly adheres to our Brand Guidelines and does not alter the original marks. Any unauthorized modification, passing off, or deliberate brand tarnishing will be subject to immediate legal action.
Digital Personal Data Protection Act, 2023 (DPDP) — Unlawful processing, theft, exfiltration, or disclosure of personal data belonging to Tradesala's sellers, customers, or any individual whose data is handled by Tradesala will attract significant penalties under this Act, based on per breach.

Tradesala Technologies Pvt Ltd reserves the right to pursue criminal prosecution, civil litigation, and injunctive relief simultaneously against perpetrators.

If you are unsure whether your intended action falls within the bounds of this policy, write to us at security@tradesala.com before proceeding.

Found something? Let us know.

We appreciate the security research community. Your responsible disclosure helps protect the data of thousands of Indian sellers and their customers who rely on our tools every day.

Report a Vulnerability

This policy is linked from /.well-known/security.txt · Last updated 7 April 2026