Security
Your data, protected
Security and privacy are built into Sahayogi from the ground up. Here is how we protect your data, your identity, and your transactions.
Security you can trust
The safeguards that keep your account and data safe.
Built with security in mind
Authentication & access control
Every account is protected by signed authentication tokens that expire automatically, and sensitive actions require a valid, active session.
Access is enforced at the server for each request — users and organizations can only see and act on the data they are authorized for, with per-member roles inside each organization.
Data protection
Traffic between your browser and our services is encrypted in transit, and user-supplied input is validated and sanitized to defend against common web attacks.
Records are soft-deleted rather than erased outright, so data can be recovered and audited rather than lost to an accidental or malicious action.
Private documents & KYC
Verification documents submitted for organization KYC are stored in a private location, separate from public images, and are never exposed through public file URLs.
They are accessible only through authenticated, ownership-checked endpoints — meaning only the people who should see a document ever can.
Privacy by design
We collect only the information needed to run the platform, and we are transparent about how it is used. Review our Privacy Policy for the full detail.
Verified listings and clear pricing mean the information you rely on to make decisions is accurate and trustworthy.
Responsible disclosure
We welcome reports from security researchers and users. If you believe you have found a vulnerability, please contact us before disclosing it publicly so we can investigate and fix it.
We will acknowledge your report, keep you updated on our progress, and credit responsible disclosure where appropriate.
Found a hole? Here is exactly what happens
The commitments below are the ones we can keep, and the same ones our machine-readable security.txt publishes.
Not an auto-reply — someone who can act on it.
Machine-readable contact and policy, per RFC 9116.
What we want tested
- The Sahayogi web app and its public pages
- The Sahayogi API, including authentication, sessions, and access control
- Anything that lets one account read or change another account’s listings, bills, payments, documents, messages, or tickets
What to leave alone
- Denial-of-service, load testing, or anything that degrades service for real users
- Automated scanner output with no demonstrated impact
- Reports against third-party services we use rather than operate — report those to their own programs
- Social engineering, phishing, or physical access attempts against our team, our users, or our offices
- Accessing, altering, or downloading data that is not your own — one screenshot proving access is enough, and is what we want instead
Safe harbour
If you research in good faith, stay inside the scope above, and give us a reasonable chance to fix an issue before disclosing it, we will not pursue or support legal action against you over it. Tell us what you found and stop there — we would rather have the report than a proof of how much data could have been taken.
Rewards, honestly
We do not run a paid bug-bounty program. We are a small team in Nepal and would rather be honest about that than advertise a reward we cannot pay. What we do offer: a human reply, a fix, and public credit if you want it.
Have a security question?
Found a vulnerability? We appreciate responsible disclosure. Email our team at support@sahayogi.io and we will respond promptly.

