What protects your account
Four safeguards are on for every account, whether or not anyone asks for them. Each one below is a specific thing the system does, not a promise about how carefully we work.
What is switched on by default
Nothing travels in the clear
Every request between your device and Sahayogi is encrypted, including the ones carrying your documents.
Sessions expire on their own
Access is a signed token with a short life, so a session left open on a shared phone stops working by itself.
KYC documents have no public URL
Verification files are stored apart from public media. There is no address that serves them, so no link can be guessed or forwarded.
An organization is checked before it can publish
A person reads an agency's registration and tax documents. Until they accept them, the profile cannot go public at all.
How each safeguard works
Authentication & access control
Every account is protected by signed authentication tokens that expire automatically, and sensitive actions require a valid, active session.
Access is enforced at the server for each request. Users and organizations can only see and act on the data they are authorized for, with per-member roles inside each organization.
Data protection
Traffic between your browser and our services is encrypted in transit, and user-supplied input is validated and sanitized to defend against common web attacks.
Records are soft-deleted rather than erased outright, so data can be recovered and audited rather than lost to an accidental or malicious action.
Private documents & KYC
Verification documents submitted for organization KYC are stored in a private location, separate from public images, and are never exposed through public file URLs.
They are accessible only through authenticated, ownership-checked endpoints, meaning only the people who should see a document ever can.
Privacy by design
We collect only the information needed to run the platform, and we are transparent about how it is used. Read our privacy policy for the full detail.
Your phone number and email are hidden by default and shown only if you choose to publish them. Until then a signed-in viewer sees a masked hint and an anonymous one sees nothing at all. A listing’s exact pin is rounded to its tole for everyone except the lister and anyone with a live deal on it.
Responsible disclosure
We welcome reports from security researchers and users. If you believe you have found a vulnerability, please contact us before disclosing it publicly so we can investigate and fix it.
We will acknowledge your report, keep you updated on our progress, and credit responsible disclosure where appropriate.
Found a hole? Here is exactly what happens
The commitments below are the ones we can keep, and the same ones our machine-readable security.txt publishes.
A human replies within 5 working days
Not an auto-reply, but someone who can act on it.
Machine-readable contact and policy, per RFC 9116.
Encrypt anything sensitive to this key before you send it.
CE44 1A24 0BFE 13FC 9339 F8CE A648 3211 84EE 5288What we want tested
- The Sahayogi web app and its public pages
- The Sahayogi API, including authentication, sessions, and access control
- Anything that lets one account read or change another account’s listings, bills, payments, documents, messages, or tickets
What to leave alone
- Denial-of-service, load testing, or anything that degrades service for real users
- Automated scanner output with no demonstrated impact
- Reports against third-party services we use rather than operate. Report those to their own programs
- Social engineering, phishing, or physical access attempts against our team, our users, or our offices
- Accessing, altering, or downloading data that is not your own. One screenshot proving access is enough, and is what we want instead
Safe harbour
If you research in good faith, stay inside the scope above, and give us a reasonable chance to fix an issue before disclosing it, we will not pursue or support legal action against you over it. Tell us what you found and stop there. We would rather have the report than a proof of how much data could have been taken.
Rewards, honestly
We do not run a paid bug-bounty program. We are a small team in Nepal and would rather be honest about that than advertise a reward we cannot pay. What we do offer: a human reply, a fix, and public credit if you want it.
Have a security question?
Found a vulnerability? We appreciate responsible disclosure. Email our team at security@sahayogi.io and we will respond promptly.