Responsible Disclosure | Supersei

Responsible Disclosure Policy

At Supersei Technologies Pvt. Ltd., the security of our platform and the trust of our users are foundational to everything we build. We genuinely value the work of independent security researchers who help us identify vulnerabilities before they can be exploited.

If you have discovered a potential security issue in any of our systems, we encourage you to report it to us responsibly. We are committed to working with you to understand, validate, and resolve the issue in a timely manner.

This policy outlines the scope of our disclosure program, how to report vulnerabilities, and what you can expect from us throughout the process.

Scope

The following assets and services are in scope for responsible disclosure:

  • supersei.com — the primary marketing and product website
  • app.supersei.com — the main SaaS application and user dashboard
  • API endpoints — all REST and GraphQL API endpoints under the api.supersei.com domain and any versioned API paths exposed to customers
  • Mobile applications — official Supersei iOS and Android apps distributed through the Apple App Store and Google Play Store

We are particularly interested in reports related to authentication and authorization flaws, data exposure, injection vulnerabilities, insecure direct object references, cross-site scripting (XSS), cross-site request forgery (CSRF), and server-side request forgery (SSRF).

Out of Scope

The following activities and targets are explicitly excluded from this program. Reports in these categories will not be considered, and actions in these areas may expose you to legal risk without safe harbor protections.

  • Social engineering attacks — phishing, vishing, smishing, or any attempt to manipulate Supersei employees or users into disclosing credentials or sensitive information
  • Denial-of-service (DoS/DDoS) attacks — any attempt to degrade, disrupt, or take down our services or infrastructure
  • Physical security — attempts to gain physical access to our offices, servers, network equipment, or personnel
  • Third-party services — vulnerabilities in external services, tools, or infrastructure we use but do not control (e.g., cloud providers, payment processors, embedded third-party scripts)
  • Automated scanning without prior permission — aggressive or intrusive automated scans that may impact service availability for other users
  • Spam and social media abuse — email flooding, form submission abuse, or manipulation of public-facing communication channels
  • Already-known issues — vulnerabilities that have already been reported and are under active remediation

How to Report

Please submit your findings by sending an email to security@supersei.ai. To help us triage and respond effectively, your report should include all of the following:

  • Description of the vulnerability — a clear and concise explanation of the issue, including the type of vulnerability (e.g., SQL injection, IDOR, XSS) and the affected component
  • Steps to reproduce — a detailed, step-by-step walkthrough that allows our security team to reliably reproduce the issue; include screenshots, HTTP request/response captures, or proof-of-concept code where applicable
  • Impact assessment — your assessment of the potential impact if the vulnerability were exploited, including what data or functionality could be affected and the severity you believe it warrants
  • Your contact information — your name (or handle), email address, and any relevant affiliations so we can communicate with you throughout the resolution process

Please encrypt sensitive reports where possible. You may request our PGP public key by emailing security@supersei.ai before submitting.

Do not submit vulnerability reports through public channels such as GitHub issues, social media, or community forums, as this may inadvertently expose the issue before a fix is in place.

What to Expect

We are committed to transparency and timely communication. Here is what you can expect after submitting a report:

  • Acknowledgment within 48 hours — you will receive a confirmation that your report has been received and assigned to our security team within two business days of submission
  • Triage within 5 business days — our team will assess the validity and severity of the report and provide an initial classification within five business days
  • Resolution timeline based on severity:
    • Critical — targeted resolution within 7 days
    • High — targeted resolution within 14 days
    • Medium — targeted resolution within 30 days
    • Low / Informational — addressed in a future release cycle, typically within 90 days
  • Status updates — we will keep you informed of progress and notify you when the vulnerability has been resolved or when a patch has been deployed

We ask for your patience if timelines need adjustment due to the complexity of a fix. We will always communicate proactively rather than go silent.

Rules of Engagement

To ensure that security research remains safe, ethical, and legally protected, all researchers must adhere to the following rules while conducting testing:

  • Do not access, modify, or destroy user data — you must not read, exfiltrate, alter, or delete data belonging to any Supersei user other than accounts you own and control for testing purposes
  • Do not disrupt services — avoid any action that could degrade performance, cause downtime, or negatively affect the experience of legitimate users
  • Do not perform public disclosure before a fix is in place — please allow us a reasonable period to remediate the issue before disclosing it publicly; coordinate any public disclosure with our team
  • Use only accounts you own or have explicit permission to test — never attempt to access, impersonate, or test using another real user's account
  • Give us reasonable time to respond — we ask that you allow at least 90 days from the date of your report before any public disclosure, in line with industry-standard coordinated disclosure practices
  • Act in good faith — your intent must be to help improve security, not to gain unauthorized access, profit from exploitation, or cause harm

Researchers who violate these rules may lose safe harbor protections and may be subject to legal action.

Safe Harbor

Supersei Technologies Pvt. Ltd. will not pursue civil or criminal legal action against security researchers who discover and report vulnerabilities in accordance with this policy.

We consider security research conducted under these guidelines to be authorized activity. If a third party initiates legal action against a researcher who has followed this policy in good faith, we will make clear that the researcher's actions were authorized and consistent with our responsible disclosure program.

Safe harbor applies only to research conducted within the defined scope, in accordance with the rules of engagement outlined above, and reported to us directly and confidentially before any public disclosure. Safe harbor does not apply to actions that involve accessing other users' data, deliberate service disruption, or violation of applicable law beyond the minimum necessary to identify and demonstrate a vulnerability.

Recognition

We deeply appreciate the time and effort security researchers invest in making our platform safer. As a token of our gratitude:

  • Hall of Fame — with your permission, we will publicly acknowledge your contribution on our Security Hall of Fame page. This recognition is optional; simply let us know your preferred name or handle and whether you wish to be listed when submitting your report
  • No monetary bounty at this time — we are a growing company and do not currently offer financial rewards for vulnerability reports. We are grateful for your understanding and hope to introduce a formal bounty program in the future as we scale
  • Direct acknowledgment — our security team will personally thank you for each valid, in-scope report, and you will be informed when the vulnerability has been resolved

We recognize that monetary compensation is an important consideration for many researchers. We are fully transparent that this is not something we currently offer, and we only welcome reports from researchers who are comfortable proceeding under these terms.

Contact

For all security-related disclosures, questions about this policy, or to request our PGP public key for encrypted communication, please reach out to our dedicated security team:

  • Email: security@supersei.ai
  • Response time: within 48 hours on business days
  • Language: English preferred

Please do not use this address for general support inquiries. For product support, visit supersei.ai/contact.

This policy was last reviewed and updated by Supersei Technologies Pvt. Ltd. and is subject to change without prior notice. We encourage researchers to review it before initiating any security testing.