SECURITY POLICY & RESPONSIBLE DISCLOSURE POLICY

LogiPhex Technologies Pvt Ltd (“LogiPhex”, “Company”, “we”, “our”, or “us”) is committed to maintaining the confidentiality, integrity, and availability of our systems, applications, APIs, and customer data.

We appreciate the efforts of security researchers and the broader security community in helping identify potential vulnerabilities. This Security Policy & Responsible Disclosure Policy explains how security concerns should be reported and how LogiPhex will respond.

1. OUR SECURITY COMMITMENT

LogiPhex continuously works to protect its platform by implementing appropriate administrative, technical, and organizational security controls.

These measures include:

  • Secure software development practices
  • HTTPS/TLS encryption
  • Authentication and authorization controls
  • API security
  • Access management
  • Database security
  • Infrastructure monitoring
  • Security logging
  • Backup and disaster recovery
  • Regular software updates
  • Vulnerability assessments
  • Risk management processes

2. RESPONSIBLE DISCLOSURE

If you believe you have discovered a security vulnerability affecting LogiPhex, we encourage you to report it responsibly.

We request that you:

  • Report the issue as soon as reasonably possible.
  • Provide sufficient technical details.
  • Allow us reasonable time to investigate and remediate.
  • Avoid public disclosure until the issue has been resolved or you receive written permission.

3. SCOPE

This Policy applies to security vulnerabilities affecting:

  • LogiPhex Website
  • Merchant Dashboard
  • Customer Portal
  • APIs
  • Mobile Applications
  • Webhooks
  • Authentication Systems
  • Admin Panels
  • Developer Portal
  • Public-facing infrastructure owned and operated by LogiPhex

4. OUT OF SCOPE

The following are generally outside the scope of this Policy:

  • Third-party websites
  • Courier partner systems
  • Marketplace partner systems
  • Internet Service Providers
  • Customer-owned infrastructure
  • Social engineering attacks
  • Physical attacks
  • Spam reports
  • Denial-of-Service testing
  • Automated vulnerability scans causing service disruption
  • Previously reported issues
  • Low-risk informational findings without a demonstrable security impact

5. RESPONSIBLE TESTING GUIDELINES

Security researchers should:

  • Act in good faith.
  • Avoid disruption of services.
  • Respect user privacy.
  • Test only their own accounts or test environments.
  • Minimize access to sensitive information.
  • Immediately stop testing if personal data is encountered.
  • Report findings promptly.

6. PROHIBITED ACTIVITIES

You must NOT:

  • Access customer data without authorization.
  • Download or copy confidential information.
  • Modify data.
  • Delete data.
  • Interfere with business operations.
  • Launch denial-of-service attacks.
  • Perform brute-force attacks.
  • Deploy malware.
  • Install backdoors.
  • Escalate privileges beyond what is necessary to demonstrate the vulnerability.
  • Attempt persistent access.
  • Compromise third-party systems.
  • Demand payment or extort LogiPhex.
  • Publicly disclose vulnerabilities before remediation.

7. INFORMATION TO INCLUDE

When reporting a vulnerability, please include:

  • Your name
  • Email address
  • Contact information
  • Date of discovery
  • Description of the issue
  • Steps to reproduce
  • Affected URL or API endpoint
  • Screenshots (if applicable)
  • Proof of concept (if available)
  • Potential impact
  • Suggested remediation (optional)

The more detailed your report, the faster we can investigate.

8. RESPONSE PROCESS

Upon receiving a valid vulnerability report, LogiPhex aims to:

  • Acknowledge receipt within a reasonable timeframe.
  • Review the submission.
  • Assess the severity.
  • Investigate the issue.
  • Implement appropriate remediation.
  • Notify the reporter when the issue has been resolved, where appropriate.

Response times may vary depending on the complexity and severity of the issue.

9. SAFE HARBOR

If you:

  • Act in good faith,
  • Comply with this Policy,
  • Avoid harming users or systems,
  • Report vulnerabilities responsibly,

LogiPhex will not initiate legal action against you solely for your responsible security research conducted in accordance with this Policy.

This Safe Harbor does not apply to illegal activities, malicious actions, or violations of applicable laws.

10. NO BUG BOUNTY PROGRAM

Unless expressly announced by LogiPhex, we do not operate a bug bounty or vulnerability reward program.

Submitting a vulnerability report does not create any entitlement to financial compensation.

LogiPhex may, at its sole discretion, acknowledge or recognize contributors for significant security findings.

11. CONFIDENTIALITY

Security reports and related communications should be treated as confidential by both parties.

Researchers should not publicly disclose vulnerabilities until:

  • The issue has been resolved, or
  • Written permission has been provided by LogiPhex.

12. CUSTOMER DATA

During security testing you must not:

  • View customer data.
  • Download customer data.
  • Modify customer data.
  • Copy personal information.
  • Share confidential information.
  • Retain any sensitive information.

If sensitive information is accessed unintentionally, cease testing immediately and report the incident.

13. SECURITY CONTROLS

LogiPhex employs security measures that may include:

  • HTTPS encryption
  • API authentication
  • Access controls
  • Firewalls
  • Security monitoring
  • Audit logs
  • Encryption of sensitive data
  • Password hashing
  • Role-based access control (RBAC)
  • Multi-factor authentication (where applicable)
  • Backup and recovery procedures
  • Continuous monitoring

Security controls may be updated periodically without prior notice.

14. THIRD-PARTY SERVICES

LogiPhex integrates with third-party providers such as:

  • Courier partners
  • Payment gateways
  • Identity verification providers
  • Cloud infrastructure providers
  • Marketplace integrations

Security issues affecting third-party systems should also be reported directly to the relevant provider where appropriate.

15. LIMITATION OF LIABILITY

This Policy does not create any contractual obligation on LogiPhex.

Nothing in this Policy limits LogiPhex’s legal rights regarding malicious, unlawful, or unauthorized activities.

16. POLICY CHANGES

LogiPhex reserves the right to modify this Security Policy & Responsible Disclosure Policy at any time.

The revised version becomes effective immediately upon publication on the official website.

17. GOVERNING LAW

This Policy shall be governed by the laws of India.

Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Navi Mumbai, Maharashtra, India.

18. CONTACT INFORMATION

Security vulnerabilities should be reported to:
LogiPhex Technologies Pvt Ltd
Email: support@logiphex.com
Website: www.logiphex.com

19. SECURITY ACKNOWLEDGEMENT

LogiPhex appreciates the efforts of security researchers who act responsibly and help improve the security of our platform.

By working together, we can create a safer and more secure logistics ecosystem for merchants, partners, developers, and customers.