Security & responsible disclosure
We take the security of IvaFlow and its customers' data seriously. If you believe you have found a vulnerability, we want to hear from you — and we commit to handling your report promptly and professionally.
How to report a vulnerability
Email your report to security@designiva.in. This mailbox is monitored by our engineering team only. Please do not report security vulnerabilities through public GitHub issues, social media or the standard support channels.
There is no need to encrypt your report — but if you prefer an encrypted channel, write to the same address and we will arrange one. Reports in English are preferred so they reach the right engineers fastest.
What to include in your report
- A clear description of the vulnerability and its impact.
- Step-by-step reproduction instructions, including URLs, parameters or payloads used.
- The affected product area (for example: dashboard, API endpoint, webhook, billing) and, if known, the affected version.
- Any evidence such as request/response logs or screenshots. Keep evidence to the minimum needed to demonstrate the issue.
- Your contact details and, if desired, a handle or alias for public acknowledgement.
You do not need to be certain the issue is exploitable — a well-documented suspicion is enough for us to start investigating.
Our response process
- 1
Acknowledgement
We acknowledge reports by email within 2 business days of receipt.
- 2
Triage
We triage the report, may ask follow-up questions, and give an initial assessment of severity within 7 business days.
- 3
Remediation
We work on a fix and keep you informed of meaningful progress. Complex fixes may take longer; we will tell you the expected timeline.
- 4
Disclosure
We publish or acknowledge the fix as described in the coordinated disclosure section below.
Coordinated disclosure
We practice coordinated disclosure. Please give us a reasonable time to fix the issue before publishing any technical detail — 90 days from your initial report is our standard window, extendable by mutual agreement. In return we commit to:
- Not pursuing legal action against researchers who follow this policy and act in good faith.
- Publicly acknowledging your contribution once the issue is fixed, if you wish to be named.
- Keeping you informed about the fix and the disclosure timeline.
We ask that you do not access, modify, copy, retain or share customer data that may be exposed by a vulnerability — demonstrating the issue with your own test account or synthetic data is always sufficient.
Permitted testing scope
Testing against IvaFlow's own web application and API endpoints is permitted within the rules below, using test accounts you create and data you own. Automated testing must be rate-limited and must not degrade the service. Any test that would affect other customers, their data or the availability of the platform is not permitted.
Prohibited testing
- Denial-of-service attempts, load testing, or any activity that degrades availability for other customers.
- Spam, phishing or social engineering against our staff, customers or partners.
- Physical attacks, or attempts to gain access to offices or data centers.
- Automated scanners run without prior coordination at a volume that affects the service.
- Vulnerabilities in third-party services we integrate with (report those to the respective vendor).
- Missing security best practices that do not have a direct, demonstrable impact (for example, absence of certain headers on static marketing pages).
Anything that involves accessing, modifying or retaining customer data is strictly prohibited. If you accidentally access data that is not yours, stop, do not store it, and tell us immediately — we will treat the accidental access itself as non-punitive when reported promptly.
Security contact
All security matters: security@designiva.in. This page and our security.txt file follow the RFC 9116 convention so researchers can always find the current, authoritative contact.