K
learn.kamaljits

Trust

Security

A short, honest summary of how we protect your account and what to do if you spot a problem.

What we do

  • HTTPS everywhere. Real Let's Encrypt certs at the load balancer; Cloudflare Full (Strict) mode.
  • Bcrypt password hashing. We never store plain-text passwords.
  • JWT sessions in HttpOnly cookies, scoped to our domain.
  • Webhook signature verification on all payment events from Dodo.
  • Rate limiting on login, signup, and password-reset endpoints.
  • Regular dependency updates and tight environment isolation between test and production.
  • We don't store payment card details — those go directly to Dodo Payments.

Reporting a vulnerability

If you find a security issue, please email [email protected].

What to include:

  • What you found (a short description plus steps to reproduce).
  • What an attacker could do with it.
  • Optional: a suggested fix.

We'll acknowledge within 2 business days and keep you posted while we investigate. Please give us a reasonable window to fix things before disclosing publicly. We won't pursue legal action against good-faith researchers.

Out of scope

The following are typically not eligible:

  • Reports from automated scanners without a clear exploit.
  • Missing security headers without a demonstrable impact.
  • Social engineering of staff or users.
  • Denial-of-service attacks.

Breach notification

In the unlikely event of a personal data breach, we'll notify the EU supervisory authority within 72 hours, India's Data Protection Board without delay, and any affected user as soon as we've assessed the impact.

Privacy · Terms · Home