Security & Responsible Disclosure

If you believe you have found a security vulnerability in Finocket, we want to hear from you before you tell anyone else. Write to support@dmstfy.com with enough detail for us to reproduce it.

What to include

What we commit to

We do not currently run a paid bug-bounty programme. We would rather say that plainly than imply a reward we do not offer.

Please do not

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised, will not pursue legal action over it, and will work with you. If a third party brings action against you for research that followed this policy, we will make that clear.

Where our data lives

Finocket runs on infrastructure in India. Customer data — books, GST records and KYC — is held in the Mumbai region and is not replicated outside India.

Machine-readable contact

The same contact details are published at /.well-known/security.txt in the format described by RFC 9116.

For privacy requests rather than security reports, see our Privacy Policy, or contact grievance@dmstfy.com.

    Security & Responsible Disclosure · Finocket