Responsible Disclosure
Last Updated: August 29, 2026
Report Security Issues
Guidelines for ethical security researchers to report system flaws or data exposure vulnerabilities.
No Disruption
Perform security testing without disrupting customer service, booking flows, or API databases.
Direct Verification
Vulnerabilities are evaluated and addressed by our local engineering lead directly.
1. Our Commitment
At TechBes, customer data security is our top priority. We appreciate the work of independent security researchers and encourage responsible reporting of any security vulnerabilities found in our mobile apps, web dashboard, or backend servers.
2. Safe Harbor Rules
We ask that researchers follow these ethical guidelines when auditing TechBes:
- Notify us immediately upon discovering a potential security issue.
- Avoid accessing customer profile details, modifying database states, or disrupting the technician booking flow.
- Give us a reasonable timeframe (at least 30 days) to address and patch the issue before making it public.
3. Out of Scope Testing
The following testing methodologies are strictly prohibited and outside the scope of our responsible disclosure policy:
- DDoS (Distributed Denial of Service) attacks or load testing that causes system downtime.
- Social engineering or phishing targeting TechBes customers, technicians, or administrators.
- Physical intrusion attempts at our office or supplier warehouses in Bangalore.
4. How to Submit a Report
If you believe you have discovered a vulnerability, please email our engineering team at lohith@techbes.co.in. Include a clear description of the issue, step-by-step instructions to reproduce it, and any proof-of-concept screenshots or scripts. We will review and acknowledge your submission within 3 business days.
