1. Security Approach
At TECHKOLA LIMITED, system security and data integrity are fundamental to our engineering process. We design our software platforms, mobile applications, and backend infrastructure to minimize risk and protect user data.
2. Core Security Practices
- Transport Security: All data transmitted between user devices and our services is encrypted using TLS/SSL protocols.
- Access Control: Administrative access to cloud hosting, production databases, and internal repositories is strictly restricted and audited.
- Code Auditing & Dependencies: Software dependencies and application binaries undergo regular static analysis and vulnerability scanning.
- Data Minimization: We restrict internal data storage to essential operational data, reducing the potential impact of any security incident.
3. Responsible Disclosure Policy
We appreciate the efforts of independent security researchers who help maintain digital system safety. If you discover a security vulnerability in any website, mobile application, or digital service operated by TECHKOLA LIMITED, we encourage you to report it responsibly.
Guidelines for Responsible Disclosure:
- Report the vulnerability as soon as practical after discovery.
- Provide sufficient technical detail (steps to reproduce, proof of concept) to allow our team to verify the issue.
- Do not access, modify, or delete user data during your investigation.
- Do not perform Denial of Service (DoS) attacks, spamming, or social engineering attacks against TechKola infrastructure or personnel.
- Allow us a reasonable time frame to investigate and address the vulnerability before public disclosure.
4. Reporting a Security Issue
Please send detailed vulnerability reports to our dedicated security contact:
TECHKOLA LIMITED Security Response Team
Security Contact Email: security@techkola.com or hello@techkola.com
Subject Line: [SECURITY REPORT] Brief description of vulnerability