Security & Responsible Disclosure
Version 1.0 · 2026-07-25
How we protect data
- HTTPS everywhere with HSTS; strict security headers and a same-origin content policy.
- QR passes use long random tokens — no personal data, amounts, or sequential IDs inside the QR.
- Payments are verified server-to-server with the provider (amount and status) — never from the browser.
- Organizer accounts support two-factor authentication; it is mandatory for platform administrators.
- One-time login codes are stored hashed and expire in minutes; abuse is rate-limited.
- Every sensitive administrative action is written to an audit log.
Reporting a vulnerability
We welcome responsible disclosure. Report issues privately — do not access other people's data or disrupt events while testing.
- WhatsApp: +977 9705510914
- Email: [email protected]
- Machine-readable: /.well-known/security.txt
We will acknowledge within 72 hours, keep you informed, and credit you if you wish once a fix ships. Good-faith research within these rules will not face legal action from us.