Security & Vulnerability Reporting

At QRParking.in, protecting the security of our platform, users, and their information is one of our highest priorities. We appreciate the efforts of security researchers, ethical hackers, developers, and responsible users who help identify potential security vulnerabilities.

This policy outlines how security issues can be responsibly reported and how QRParking.in handles such reports.

Purpose

The purpose of this policy is to:

  • Encourage responsible disclosure of security vulnerabilities.
  • Protect users and the platform from potential security threats.
  • Establish a transparent reporting process.
  • Ensure timely investigation and remediation of reported vulnerabilities.
  • Promote a secure digital environment for all users.

What Should Be Reported?

We encourage responsible reporting of security vulnerabilities including, but not limited to:

  • Unauthorized access vulnerabilities
  • Authentication or login issues
  • Account takeover risks
  • Privilege escalation vulnerabilities
  • Cross-Site Scripting (XSS)
  • SQL Injection
  • Cross-Site Request Forgery (CSRF)
  • Remote Code Execution (RCE)
  • Sensitive information exposure
  • API security vulnerabilities
  • Server misconfigurations
  • Authentication bypass
  • Broken access controls
  • Security flaws affecting QR code functionality

If you believe you have discovered any security weakness, please report it responsibly.

Responsible Disclosure Guidelines

We request that all security researchers act responsibly by:

  • Reporting vulnerabilities privately before publicly disclosing them.
  • Allowing us reasonable time to investigate and resolve the issue.
  • Avoiding actions that could disrupt our services.
  • Not accessing, modifying, or deleting user data.
  • Not exploiting vulnerabilities beyond what is necessary to demonstrate their existence.
  • Respecting user privacy at all times.

Information to Include in Your Report

To help us investigate efficiently, please provide:

  • Your Name (optional)
  • Email Address
  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected page or URL
  • Screenshots or proof of concept (if available)
  • Browser and operating system used
  • Any additional technical details that may assist our investigation

Clear and detailed reports help us resolve issues more quickly.

Investigation Process

Upon receiving a vulnerability report, QRParking.in will:

  1. Acknowledge receipt of the report.
  2. Review the submitted information.
  3. Verify the reported vulnerability.
  4. Assess the potential impact.
  5. Prioritize remediation based on severity.
  6. Implement necessary fixes.
  7. Close the report after verification.

Where appropriate, we may contact the reporter for additional information during the investigation.

Response Timeline

While investigation times may vary depending on complexity, we generally aim to:

  • Acknowledge reports within 48 business hours.
  • Begin investigation promptly after verification.
  • Resolve confirmed vulnerabilities as quickly as reasonably possible.
  • Inform the reporter once the issue has been addressed, where appropriate.

Activities Not Permitted

While testing our platform, please do not:

  • Access another user's account.
  • Download or copy confidential data.
  • Modify or delete information belonging to other users.
  • Perform denial-of-service (DoS or DDoS) attacks.
  • Introduce malware or malicious code.
  • Disrupt platform availability.
  • Attempt social engineering against our employees or customers.
  • Use automated tools in a manner that affects platform performance.

Unauthorized or malicious activities may result in legal action.

Safe Harbor

QRParking.in appreciates responsible security research conducted in good faith.

We will not pursue legal action against individuals who:

  • Follow this policy.
  • Report vulnerabilities responsibly.
  • Avoid compromising user privacy.
  • Do not exploit vulnerabilities for personal gain.
  • Cooperate during the investigation process.

This Safe Harbor statement does not apply to illegal activities or intentional misuse.

Our Commitment

QRParking.in is committed to:

  • Maintaining strong security practices.
  • Investigating reported vulnerabilities promptly.
  • Protecting user information.
  • Continuously improving platform security.
  • Working collaboratively with responsible security researchers.

Policy Updates

This Security & Vulnerability Reporting Policy may be updated periodically to reflect improvements in our security practices or changes in applicable laws.

Users are encouraged to review this page from time to time.

Contact Us

To report a security vulnerability, please contact:

QRParking.in

Official Email: info@qrparking.in

Office Address:

Office No. 1503
Galaxy Diamond Plaza
Uttar Pradesh – 201016

Please include sufficient technical details to help us investigate the reported issue effectively.

Acknowledgement

By reporting a vulnerability to QRParking.in, you agree to follow the responsible disclosure principles outlined in this policy. We appreciate your efforts in helping us maintain a secure and trustworthy platform for all users.