Responsible Disclosure Policy
Last updated: 24 September 2026
Customers trust us with their documents, addresses and payments. If you believe you have found a security vulnerability in Printster, please tell us privately so we can fix it before anyone is harmed. We will not take legal action against researchers who follow this policy in good faith.
How to report
- Email: info@printster.in with the subject line “Security vulnerability report”
- Our machine-readable contact file is at /.well-known/security.txt
Please include:
- The affected URL, app screen or API endpoint
- A description of the issue and its likely impact
- Step-by-step instructions to reproduce it, with any proof-of-concept code or screenshots
- How you would like to be credited, if at all
In scope
- The Printster website, ordering app and customer account pages
- The Printster API used by our website and apps
- The Printster WhatsApp ordering bot
Out of scope
- Third-party services we use, such as our payment gateway, couriers and email providers. Please report those to the vendor directly.
- Denial-of-service attacks, load testing, spam or social engineering of our staff or customers
- Physical attacks on our offices or print facilities
- Reports from automated scanners without a demonstrated impact
- Missing best-practice headers or cookie flags with no demonstrated exploit, clickjacking on pages with no sensitive action, and self-XSS
Rules for testing
- Only test against accounts and orders you own, or that you create for testing.
- Never access, change, download or delete another customer’s files, orders or personal data. If you accidentally see such data, stop, do not keep a copy, and tell us in your report.
- Do not place real orders you do not intend to pay for, and do not attempt to obtain free goods, discounts or wallet credit.
- Do not degrade the service for other users.
- Give us a reasonable time to fix the issue before sharing details with anyone else.
What you can expect from us
| Step | Our target |
|---|---|
| Acknowledge your report | Within 3 working days |
| Confirm whether the issue is valid and share our assessment | Within 10 working days |
| Fix critical and high-severity issues | As a priority, and we will keep you updated |
We do not currently run a paid bug bounty. With your permission, we are happy to thank you publicly once the issue is fixed.
Safe harbour
If you make a good-faith effort to follow this policy, we will consider your research authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. This does not authorise testing that breaks the law or violates the privacy of others.