Vulnerability Disclosure Policy
Indoh Market Data welcomes responsible reports from security researchers.
Scope
This policy applies to security vulnerabilities in:
- Our public website and web application at indohmarketdata.co.za
- Authenticated product features served under that domain
- Our API endpoints operated for the Indoh Market Data platform
Out of scope: third-party services we do not operate, social engineering against individuals, physical attacks, and denial-of-service tests.
How to report
- Email security@indohmarketdata.co.za with a clear description, steps to reproduce, and impact assessment.
- Include URLs, request/response samples, screenshots, or proof-of-concept only as needed to demonstrate the issue.
- Encrypt sensitive details with our OpenPGP key when published at
/.well-known/security-pgp.asc (see Encryption in security.txt).
Safe harbour
We will not pursue legal action against researchers who:
- Act in good faith and follow this policy
- Avoid privacy violations, data destruction, and service disruption
- Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability
- Give us reasonable time to remediate before any public disclosure
What we ask you not to do
- Automated scanning that degrades production performance
- Testing on accounts or data you do not own without explicit written permission
- Spam, phishing, or social engineering of staff or customers
Our commitment
- Acknowledgement: within 3 business days of a valid report
- Status updates: as investigation progresses, typically every 10 business days
- Remediation: prioritized by severity; critical issues addressed as quickly as practicable
- Credit: with your permission, we may acknowledge your contribution after a fix is deployed
Severity guidance
- Critical: unauthenticated remote code execution, authentication bypass, mass credential disclosure
- High: SQL injection, stored XSS in authenticated areas, privilege escalation
- Medium: CSRF with meaningful impact, information disclosure of non-public data
- Low: missing best-practice headers, low-impact UI issues without security boundary crossing
Out of scope (examples)
- Missing security headers without demonstrated exploit
- Clickjacking on pages with no sensitive actions
- Reports from automated tools without manual validation
- Issues in outdated browsers or unsupported client versions
Contact
Security reports: security@indohmarketdata.co.za
For general support, use in-app help or your usual support channel — not this mailbox.