Ghuzar handles real user data and real financial transactions. If you find a vulnerability, we want to know — this page tells you how to report it and what to expect from us.
How to report
Email us at:
security@ghuzar.comInclude as much detail as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce it
- The affected version, URL or endpoint
- Any screenshots or logs that help
What happens next
- We confirm receipt of your report
- We verify it and get back to you with our assessment
- We fix impactful vulnerabilities as fast as we can
- We let you know when the fix ships
If you like, we credit you by name after the fix — or keep you anonymous, as you prefer.
Responsible disclosure
We ask you not to publish the vulnerability before we fix it — so our users are not exposed in the meantime. We take every report seriously and do not respond with legal threats to researchers who report in good faith.
Things we ask you not to do
- Do not access, modify or delete real users' data
- Do not run flooding or denial-of-service attacks
- Do not use social engineering on users or our team
- If you reach data by accident, stop immediately, tell us, and do not keep it
Scope
Everything on ghuzar.com, api.ghuzar.com and the com.ghuzar.app application.
The third-party services we rely on (Supabase · Cloudflare · Cloudinary · Paymob · Firebase) have their own programmes — report to them directly, and tell us too if the issue affects us.