Sahayogi
Skip to content

Security

Your data, protected

Security and privacy are built into Sahayogi from the ground up. Here is how we protect your data, your identity, and your transactions.

How we protect you

Security you can trust

The safeguards that keep your account and data safe.

Encrypted in Transit

All traffic between your device and our servers is protected, keeping your information private end to end.

Token-Based Authentication

Signed, expiring access tokens guard every request, so only you can act on your account.

Private Document Vault

Sensitive KYC documents are stored apart from public files and never served over public URLs.

Verified Identities

Agents and builders are verified through document-backed KYC before they can transact with you.

Our practices

Built with security in mind

Authentication & access control

Every account is protected by signed authentication tokens that expire automatically, and sensitive actions require a valid, active session.

Access is enforced at the server for each request — users and organizations can only see and act on the data they are authorized for, with per-member roles inside each organization.

Data protection

Traffic between your browser and our services is encrypted in transit, and user-supplied input is validated and sanitized to defend against common web attacks.

Records are soft-deleted rather than erased outright, so data can be recovered and audited rather than lost to an accidental or malicious action.

Private documents & KYC

Verification documents submitted for organization KYC are stored in a private location, separate from public images, and are never exposed through public file URLs.

They are accessible only through authenticated, ownership-checked endpoints — meaning only the people who should see a document ever can.

Privacy by design

We collect only the information needed to run the platform, and we are transparent about how it is used. Review our Privacy Policy for the full detail.

Verified listings and clear pricing mean the information you rely on to make decisions is accurate and trustworthy.

Responsible disclosure

We welcome reports from security researchers and users. If you believe you have found a vulnerability, please contact us before disclosing it publicly so we can investigate and fix it.

We will acknowledge your report, keep you updated on our progress, and credit responsible disclosure where appropriate.

Responsible disclosure

Found a hole? Here is exactly what happens

The commitments below are the ones we can keep, and the same ones our machine-readable security.txt publishes.

A human replies within 5 working days

Not an auto-reply — someone who can act on it.

security.txt

Machine-readable contact and policy, per RFC 9116.

What we want tested

  • The Sahayogi web app and its public pages
  • The Sahayogi API, including authentication, sessions, and access control
  • Anything that lets one account read or change another account’s listings, bills, payments, documents, messages, or tickets

What to leave alone

  • Denial-of-service, load testing, or anything that degrades service for real users
  • Automated scanner output with no demonstrated impact
  • Reports against third-party services we use rather than operate — report those to their own programs
  • Social engineering, phishing, or physical access attempts against our team, our users, or our offices
  • Accessing, altering, or downloading data that is not your own — one screenshot proving access is enough, and is what we want instead

Safe harbour

If you research in good faith, stay inside the scope above, and give us a reasonable chance to fix an issue before disclosing it, we will not pursue or support legal action against you over it. Tell us what you found and stop there — we would rather have the report than a proof of how much data could have been taken.

Rewards, honestly

We do not run a paid bug-bounty program. We are a small team in Nepal and would rather be honest about that than advertise a reward we cannot pay. What we do offer: a human reply, a fix, and public credit if you want it.

Have a security question?

Found a vulnerability? We appreciate responsible disclosure. Email our team at support@sahayogi.io and we will respond promptly.