# MazdaDev security disclosure policy. # RFC 9116 — https://datatracker.ietf.org/doc/rfc9116/ # # If you find a security issue in mazdadev.in, in any tool we ship, # or in the CreatorKit AI backend, please report it privately through # the channels below. We commit to acknowledging every report within # 3 business days and providing a status update within 7 days. # # Do NOT open a public GitHub issue for anything with security impact. # Do NOT test payloads on real user accounts other than your own. # Automated scans are welcome but please throttle to avoid rate limits. Contact: mailto:support@mazdadev.in Contact: https://mazdadev.in/contact Preferred-Languages: en, hi Canonical: https://mazdadev.in/.well-known/security.txt Policy: https://mazdadev.in/privacy Acknowledgments: https://mazdadev.in/#thanks # Scope # - mazdadev.in and every subdomain we own. # - The CreatorKit AI mobile app (iOS + Android) and its webviews. # - Public MazdaDev endpoints and any published integration. # # Out of scope # - Third-party services we integrate with (Razorpay, PayPal, Cashfree, # OpenAI, etc.). Report those directly to the respective vendor. # - Social-engineering, physical, or DoS attacks. # - Reports about missing CSP nonces / X-Frame-Options / cookie flags # without a demonstrable exploit chain. # We do not yet run a paid bug-bounty programme, but every valid # responsible disclosure will be publicly credited on request. # This document expires 12 months from publication; we'll refresh it # on each deployment. Expires: 2027-08-31T00:00:00Z