←
Policy

Security & responsible disclosure

RFC 9116 · in effect Aug 2026 → Aug 2027

If you've found a security issue in KitnaKaafi, we'd rather hear from you first, quietly. Good-faith research is welcome, and the safe-harbor terms below apply.

How to report

Email nitin.goswami@gmail.com with:

  • a description of the issue,
  • steps to reproduce (ideally with a minimal repro),
  • the impact you believe it has, and
  • your preferred credit name if you'd like acknowledgement.

We aim to acknowledge within 72 hours and to have a fix or a mitigation plan within 30 days. For critical issues affecting user privacy or data integrity, we treat it as higher-priority.

Machine-readable pointer

A standards-compliant security.txt lives at /.well-known/security.txt per RFC 9116.

In scope

  • kitnakaafi.tech and any preview deployment on *.vercel.app associated with this project
  • All routes served by the Next.js app (calculators, Intelligent Mode, editorial pages, API endpoints at /api/contact and /api/subscribe)
  • Issues in the engine math that could produce misleading financial output (please cite the input parameters)
  • Any way you can extract user input from the site (URL, log, cookie, referer, RSC payload, etc.) — the whole privacy posture depends on this being impossible

Out of scope

  • Denial-of-service or volumetric attacks — please don't
  • Social engineering of the operator or any third-party service (Vercel, Brevo, Upstash)
  • Physical attacks on the operator's hardware
  • Vulnerabilities in third-party services themselves — report those directly to Vercel / Brevo / Upstash
  • Missing best-practice security headers that don't translate into an actual exploit path
  • Automated scanner output pasted verbatim without a demonstrated impact

Safe harbor

If you make a good-faith effort to comply with this policy while researching a KitnaKaafi security issue, we will:

  • consider your research to be authorised under applicable Indian law,
  • work with you to understand and resolve the issue promptly,
  • not pursue or support any legal action related to your research, and
  • publicly credit you (with your permission) once the issue is fixed.

Good-faith means: give us a reasonable time to fix before public disclosure, do not intentionally exfiltrate user data beyond what is necessary to prove the issue, and do not degrade the service for other users.

What we can't offer

KitnaKaafi is operated by an individual, not a company. There is no bug-bounty program with monetary rewards. Recognition, acknowledgement, and a heartfelt thank-you are what we can offer.

Hall of fame

To be populated as researchers report issues. You could be the first.