Found a vulnerability? Tell us.
We'd rather hear it from you than read about it. Here's how to reach us and what happens next.
How to reach us.
Email security@snappcab.in with enough detail to reproduce the issue: the endpoint or screen, the steps, and what you were able to do that you shouldn’t have been.
Please report privately and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against anyone who reports in good faith and follows the guidelines below.
What we’ll do
- Acknowledge your report within 3 working days.
- Tell you whether we’ve reproduced it, and our assessment of the severity.
- Keep you updated while we fix it, and tell you when it’s shipped.
- Credit you if you’d like to be credited.
Please don’t
- Access, modify or delete data belonging to anyone but yourself.
- Run denial-of-service tests, or any test that degrades service for real users.
- Social-engineer our staff, captains or riders, or attempt physical access to our premises.
- Use automated scanners that generate high-volume traffic against production.
Out of scope
Reports that consist only of automated scanner output with no demonstrated impact, missing security headers with no exploitable consequence, or issues in third-party services we don’t control.
Not a security issue?
If it’s a bug rather than a vulnerability, the support formis the right place — choose “Report a bug” and it reaches the same team that fixes them.