LogiPhex Technologies Pvt Ltd (“LogiPhex”, “Company”, “we”, “our”, or “us”) is committed to maintaining the confidentiality, integrity, and availability of our systems, applications, APIs, and customer data.
We appreciate the efforts of security researchers and the broader security community in helping identify potential vulnerabilities. This Security Policy & Responsible Disclosure Policy explains how security concerns should be reported and how LogiPhex will respond.
1. OUR SECURITY COMMITMENT
LogiPhex continuously works to protect its platform by implementing appropriate administrative, technical, and organizational security controls.
These measures include:
- Secure software development practices
- HTTPS/TLS encryption
- Authentication and authorization controls
- API security
- Access management
- Database security
- Infrastructure monitoring
- Security logging
- Backup and disaster recovery
- Regular software updates
- Vulnerability assessments
- Risk management processes
2. RESPONSIBLE DISCLOSURE
If you believe you have discovered a security vulnerability affecting LogiPhex, we encourage you to report it responsibly.
We request that you:
- Report the issue as soon as reasonably possible.
- Provide sufficient technical details.
- Allow us reasonable time to investigate and remediate.
- Avoid public disclosure until the issue has been resolved or you receive written permission.
3. SCOPE
This Policy applies to security vulnerabilities affecting:
- LogiPhex Website
- Merchant Dashboard
- Customer Portal
- APIs
- Mobile Applications
- Webhooks
- Authentication Systems
- Admin Panels
- Developer Portal
- Public-facing infrastructure owned and operated by LogiPhex
4. OUT OF SCOPE
The following are generally outside the scope of this Policy:
- Third-party websites
- Courier partner systems
- Marketplace partner systems
- Internet Service Providers
- Customer-owned infrastructure
- Social engineering attacks
- Physical attacks
- Spam reports
- Denial-of-Service testing
- Automated vulnerability scans causing service disruption
- Previously reported issues
- Low-risk informational findings without a demonstrable security impact
5. RESPONSIBLE TESTING GUIDELINES
Security researchers should:
- Act in good faith.
- Avoid disruption of services.
- Respect user privacy.
- Test only their own accounts or test environments.
- Minimize access to sensitive information.
- Immediately stop testing if personal data is encountered.
- Report findings promptly.
6. PROHIBITED ACTIVITIES
You must NOT:
- Access customer data without authorization.
- Download or copy confidential information.
- Modify data.
- Delete data.
- Interfere with business operations.
- Launch denial-of-service attacks.
- Perform brute-force attacks.
- Deploy malware.
- Install backdoors.
- Escalate privileges beyond what is necessary to demonstrate the vulnerability.
- Attempt persistent access.
- Compromise third-party systems.
- Demand payment or extort LogiPhex.
- Publicly disclose vulnerabilities before remediation.
7. INFORMATION TO INCLUDE
When reporting a vulnerability, please include:
- Your name
- Email address
- Contact information
- Date of discovery
- Description of the issue
- Steps to reproduce
- Affected URL or API endpoint
- Screenshots (if applicable)
- Proof of concept (if available)
- Potential impact
- Suggested remediation (optional)
The more detailed your report, the faster we can investigate.
8. RESPONSE PROCESS
Upon receiving a valid vulnerability report, LogiPhex aims to:
- Acknowledge receipt within a reasonable timeframe.
- Review the submission.
- Assess the severity.
- Investigate the issue.
- Implement appropriate remediation.
- Notify the reporter when the issue has been resolved, where appropriate.
Response times may vary depending on the complexity and severity of the issue.
9. SAFE HARBOR
If you:
- Act in good faith,
- Comply with this Policy,
- Avoid harming users or systems,
- Report vulnerabilities responsibly,
LogiPhex will not initiate legal action against you solely for your responsible security research conducted in accordance with this Policy.
This Safe Harbor does not apply to illegal activities, malicious actions, or violations of applicable laws.
10. NO BUG BOUNTY PROGRAM
Unless expressly announced by LogiPhex, we do not operate a bug bounty or vulnerability reward program.
Submitting a vulnerability report does not create any entitlement to financial compensation.
LogiPhex may, at its sole discretion, acknowledge or recognize contributors for significant security findings.
11. CONFIDENTIALITY
Security reports and related communications should be treated as confidential by both parties.
Researchers should not publicly disclose vulnerabilities until:
- The issue has been resolved, or
- Written permission has been provided by LogiPhex.
12. CUSTOMER DATA
During security testing you must not:
- View customer data.
- Download customer data.
- Modify customer data.
- Copy personal information.
- Share confidential information.
- Retain any sensitive information.
If sensitive information is accessed unintentionally, cease testing immediately and report the incident.
13. SECURITY CONTROLS
LogiPhex employs security measures that may include:
- HTTPS encryption
- API authentication
- Access controls
- Firewalls
- Security monitoring
- Audit logs
- Encryption of sensitive data
- Password hashing
- Role-based access control (RBAC)
- Multi-factor authentication (where applicable)
- Backup and recovery procedures
- Continuous monitoring
Security controls may be updated periodically without prior notice.
14. THIRD-PARTY SERVICES
LogiPhex integrates with third-party providers such as:
- Courier partners
- Payment gateways
- Identity verification providers
- Cloud infrastructure providers
- Marketplace integrations
Security issues affecting third-party systems should also be reported directly to the relevant provider where appropriate.
15. LIMITATION OF LIABILITY
This Policy does not create any contractual obligation on LogiPhex.
Nothing in this Policy limits LogiPhex’s legal rights regarding malicious, unlawful, or unauthorized activities.
16. POLICY CHANGES
LogiPhex reserves the right to modify this Security Policy & Responsible Disclosure Policy at any time.
The revised version becomes effective immediately upon publication on the official website.
17. GOVERNING LAW
This Policy shall be governed by the laws of India.
Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Navi Mumbai, Maharashtra, India.
18. CONTACT INFORMATION
Security vulnerabilities should be reported to: LogiPhex Technologies Pvt Ltd Email: support@logiphex.com Website: www.logiphex.com
19. SECURITY ACKNOWLEDGEMENT
LogiPhex appreciates the efforts of security researchers who act responsibly and help improve the security of our platform.
By working together, we can create a safer and more secure logistics ecosystem for merchants, partners, developers, and customers.