← Aarulya Saathi

Security and Incident Response

Report suspected vulnerabilities, unauthorised access, data exposure, phishing, impersonation, or security incidents to security@aarulya.com.

Safe reporting

Include the affected URL or feature, date/time, reproducible steps, impact, and non-sensitive evidence. Do not exploit beyond what is necessary to demonstrate the issue. Do not access another person’s data, disrupt service, publish secrets, or demand payment.

Response approach

Affected integrations or deployments may be stopped, logs and exact commit/image evidence preserved, credentials rotated, access revoked, and verified backups used for recovery. Safety controls are not bypassed merely to restore a feature quickly.

Security boundary

The production design uses HTTPS, restricted public ports, mounted secrets, separate database roles, forced row-level security, encrypted backups, health checks, and rollback evidence. Founder/owner services remain on a separate private lane unless explicitly activated.

Emergency warning

Do not use email for an immediate threat to life or physical safety; contact the appropriate local emergency authority.