Security reporting

Help us protect Chalo users.

Report a potential security vulnerability affecting Chalo through a clear, responsible channel.

What to include

Describe the affected Chalo URL or feature, reproduction steps, impact, and any supporting request or response evidence. Do not include unnecessary personal data.

Safe testing

Use accounts and data you control. Avoid privacy violations, service disruption, automated high-volume traffic, social engineering, and destructive testing.

How to report

Choose Security issue on the contact page or email info@chalo.dev with “Security disclosure” in the subject.

What to expect

Chalo will acknowledge a valid report and coordinate follow-up based on severity. No fixed response-time or bounty promise is made on this page.

Scanner results

A missing header or public website finding is not automatically a vulnerability in Chalo. Include why the issue affects Chalo users or systems.

Public disclosure

Allow reasonable time for investigation and remediation before publishing details. Coordinate disclosure timing with Chalo.