Security

Found a vulnerability? Tell us.

We'd rather hear it from you than read about it. Here's how to reach us and what happens next.

Reporting

How to reach us.

Email security@snappcab.in with enough detail to reproduce the issue: the endpoint or screen, the steps, and what you were able to do that you shouldn’t have been.

Please report privately and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against anyone who reports in good faith and follows the guidelines below.

What we’ll do

  • Acknowledge your report within 3 working days.
  • Tell you whether we’ve reproduced it, and our assessment of the severity.
  • Keep you updated while we fix it, and tell you when it’s shipped.
  • Credit you if you’d like to be credited.

Please don’t

  • Access, modify or delete data belonging to anyone but yourself.
  • Run denial-of-service tests, or any test that degrades service for real users.
  • Social-engineer our staff, captains or riders, or attempt physical access to our premises.
  • Use automated scanners that generate high-volume traffic against production.

Out of scope

Reports that consist only of automated scanner output with no demonstrated impact, missing security headers with no exploitable consequence, or issues in third-party services we don’t control.

Not a security issue?

If it’s a bug rather than a vulnerability, the support formis the right place — choose “Report a bug” and it reaches the same team that fixes them.