What to include
Describe the affected Chalo URL or feature, reproduction steps, impact, and any supporting request or response evidence. Do not include unnecessary personal data.
Security reporting
Report a potential security vulnerability affecting Chalo through a clear, responsible channel.
Describe the affected Chalo URL or feature, reproduction steps, impact, and any supporting request or response evidence. Do not include unnecessary personal data.
Use accounts and data you control. Avoid privacy violations, service disruption, automated high-volume traffic, social engineering, and destructive testing.
Choose Security issue on the contact page or email info@chalo.dev with “Security disclosure” in the subject.
Chalo will acknowledge a valid report and coordinate follow-up based on severity. No fixed response-time or bounty promise is made on this page.
A missing header or public website finding is not automatically a vulnerability in Chalo. Include why the issue affects Chalo users or systems.
Allow reasonable time for investigation and remediation before publishing details. Coordinate disclosure timing with Chalo.