Lahore · Pakistan
Security Policy
We take the security of this website and the personal information entrusted to us seriously. If you believe you have discovered a vulnerability, please report it responsibly using the contacts listed at /.well-known/security.txt or through the contact form on the Contact page.
Please include steps to reproduce, the affected URL, and any proof-of-concept material. Do not access, modify, or exfiltrate data belonging to other users. Do not run automated scans that degrade service for others.
We aim to acknowledge reports within five business days and to keep researchers informed as we investigate. We do not currently offer monetary bounties, but we credit researchers who report in good faith and give us reasonable time to remediate before public disclosure.
Out of scope: denial-of-service attacks, physical attacks, social engineering of staff, and issues that require an already-compromised device or account. Reports that violate applicable law will not be acknowledged.