Secure the Collective
We take security seriously. If you believe you've found a vulnerability across our infrastructure, we encourage you to report it via the form below or by emailing security@kavach.org. We validate and reward coordinated disclosures.
In-Scope Assets
- *.kavach.dev
- api.kavach.dev
- K.A.V.A.C.H. Dashboard Authentication Flow
- Role-Based Access Control (RBAC)
Out of Scope
Denial of Service (DoS/DDoS) attacks against any Kavach infrastructure.
Social Engineering, Phishing, or physical attacks against students/staff.
Vulnerabilities in third-party services (e.g., Supabase, Vercel) unless misconfigured by us.
Clickjacking on pages with no sensitive actions, or Self-XSS.
Hall of Fame
Valid security disclosures are rewarded with an official spot on our Hall of Fame and specialized Discord roles.
Safe Harbor
Activities conducted in good faith and in accordance with this policy will be considered authorized. We will not initiate legal action against you.