Effective: 7 April 2026Scope: For all Tradesala productsVersion: 1.0
At Tradesala Technologies Pvt Ltd, we build tools used by thousands of Indian sellers
every day. Security is not an afterthought — it is a core commitment. We welcome responsible security
research and are grateful to researchers who help us keep our platform and our sellers safe.
This policy explains what we consider to be in scope, how to report a vulnerability, what you can expect from
us, and what we ask of you in return.
Scope
✓ In Scope
tools.tradesala.store and all subdomains
tradesala.com and all subdomains
Tradesala mobile apps (Android / iOS)
Authentication and session management
API endpoints and data exposure
Cross-site scripting (XSS)
SQL injection and server-side vulnerabilities
Seller account data, business details &
financials
Customer / buyer personal data & order
information
Any data processed, stored, or transmitted by
Tradesala
✕ Out of Scope
Denial of service (DoS / DDoS) attacks
Physical security of our offices
Social engineering of Tradesala staff
Third-party services we do not control
Automated scanner output without PoC
Self-XSS with no real-world impact
Rate limiting on non-sensitive endpoints
Missing security headers (low severity)
Data We Are Committed to Protecting
Tradesala handles sensitive data on behalf of thousands of Indian sellers and their customers. Any
vulnerability that touches the following categories is treated with the highest priority and
must be reported immediately to security@tradesala.com.
Seller Data
Seller business details
— company name, address, GSTIN, PAN, bank account information
Seller login
credentials, session tokens, and account access
Sales data, order
history, revenue figures, and financial records
Inventory data, product
catalogues, pricing, and supplier information
Customer / Buyer Data
Buyer personal details
— full name, phone number, email address
Delivery addresses and
pincode data
Order details, payment
mode (COD / prepaid), and transaction history
Any personally
identifiable information (PII) as defined under the DPDP Act, 2023
Platform & Operational Data
Internal system
configurations, infrastructure details, or API keys
Tradesala employee
credentials or internal communication systems
Any data processed,
stored, or transmitted by Tradesala on behalf of any party
If you accidentally access any of the above data while conducting research, stop immediately, do
not copy or retain it, and disclose this in your report. We will not penalise accidental access
reported in good faith.
How to Report
Please send all vulnerability reports to security@tradesala.com
with the subject line Security Vulnerability Report. This inbox is monitored by our
engineering team, not our legal team — your report reaches the right people immediately. We prefer reports in
English, Tamil, or Hindi.
Include in your report
1
Vulnerability description
Type of issue (e.g. XSS, IDOR, SQL injection), affected URL or component, and its
potential impact on sellers or Tradesala.
2
Reproduction steps
Clear, numbered steps to reproduce the issue. Include the HTTP request/response
if relevant.
3
Proof of concept
Screenshots, screen recordings, or a minimal PoC. Do not access, modify, or
delete real user data beyond what is needed to demonstrate the issue.
4
Your contact details
Name (or handle) and a reply email. We'll use this to send you updates and
acknowledgement.
Response Timelines
We take every report seriously. Our committed response timelines by severity are:
Severity
Examples
Initial Response
Target Resolution
Critical
RCE, auth bypass, mass data leak
Within 48 hours
15 days or more
High
IDOR, stored XSS, privilege escalation
Within 72 hours
15 days or more
Medium
Reflected XSS, CSRF, info disclosure
Within 72 hours
30 days or more
Low
Best-practice gaps, low-impact issues
Within 5 days
90 days or more
We will keep you updated if a fix requires more time than the target above, and will
not go silent on valid reports.
Our Commitments to You
✓
We will not pursue legal action
Researchers who follow this policy and act in good faith will not face legal
action from Tradesala under India's IT Act or any other law.
✓
We will acknowledge every valid report
Valid reports will be acknowledged by name or handle (your choice) in our
security acknowledgements page once the fix is shipped.
✓
We will keep you in the loop
We will share our assessment of the issue, our fix timeline, and notify you when
the vulnerability has been resolved.
✓
We will work with you on disclosure timing
We follow coordinated disclosure. We ask for a reasonable embargo period
(typically 90 days for non-critical issues) before public disclosure.
What We Ask of You
To be covered under this policy, please act in good faith and follow these guidelines:
Do not access, copy, download, modify,
or delete data belonging to sellers, customers, or Tradesala beyond the absolute minimum needed to
demonstrate the vulnerability.
Do not perform denial-of-service
attacks, spam, or any action that degrades the experience for our sellers or their customers.
Do not publicly disclose the
vulnerability before we have had a reasonable opportunity to fix it.
Do not use automated scanners against
our production systems without prior written permission.
Do not conduct research on seller or
customer accounts that do not belong to you. Create your own test account for testing.
If you inadvertently access seller
financials, Customer Personally Identifiable Information (PII), or any other sensitive data, disclose this
immediately in your report and do not
retain copies.
Legal & Jurisdiction
Tradesala Technologies Pvt Ltd is incorporated in India (CIN: U74999TN2020PTC137626),
registered in Chennai, Tamil Nadu. This policy is governed by the laws of India, including the Information
Technology Act, 2000 and its amendments.
Security researchers who act in good faith and within the boundaries of this policy are explicitly authorised
to conduct the research described above on our in-scope systems. Tradesala will not initiate legal proceedings
against researchers who comply with this policy.
Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in
Chennai, Tamil Nadu, India.
Zero Tolerance for Malicious Activity
This policy exists to support responsible, good-faith security research. It is not a
licence for malicious conduct of any kind.
Any individual, entity, or group that intentionally and maliciously targets Tradesala Technologies Pvt Ltd,
its products, platforms, sellers, customers, or associated services — including but not limited to acts of
hacking, unauthorised access, theft of seller or customer data, financial data exfiltration, system
tampering, service disruption, brand tarnishing, reputation damage, defacement, or coordinated
attacks — will be subject to the full force of applicable law.
Applicable Laws — India
Information
Technology Act, 2000 — Sections 43, 66, 66B, 66C, 66D, 66F — covering unauthorised access, data
theft, identity fraud, cyberterrorism, and computer damage. Punishable by imprisonment of up to 7 years
and/or fine.
Indian Penal
Code (IPC) / Bharatiya Nyaya Sanhita, 2023 — Sections covering criminal breach of trust,
cheating, forgery, and conspiracy applicable to digital fraud and theft.
Trade Marks
Act, 1999 — The Tradesala brand, logo, and associated marks are protected intellectual
property.
We permit the use of our logos for promotional social media and advertising, provided the use strictly
adheres to our Brand Guidelines and does not alter the original marks.
Any unauthorized modification, passing off, or deliberate brand tarnishing will be subject to immediate
legal action.
Digital
Personal Data Protection Act, 2023 (DPDP) — Unlawful processing, theft, exfiltration, or
disclosure of personal data belonging to Tradesala's sellers, customers, or any individual whose data is
handled by Tradesala will attract significant penalties under this Act, based on per breach.
Tradesala Technologies Pvt Ltd reserves the right to pursue criminal prosecution, civil litigation,
and injunctive relief simultaneously against perpetrators.
If you are unsure whether your intended action falls within the bounds of this policy, write to us at security@tradesala.com before proceeding.
Found something? Let us know.
We appreciate the security research community. Your responsible disclosure helps protect the data of
thousands of Indian sellers and their customers who rely on our tools every day.