Security and Vulnerability Disclosure
- Report to
- security@angyal.in
- Acknowledged in
- 1–2 business days
- Disclosure
- Coordinated — 90 days is the norm
- Reward
- No bug bounty; credit on request
- Last updated
If you have found a security problem in this website or in an Angyal app, we want to hear about it. This page tells you where to send it, what we ask while you are looking, and what you can expect from us in return.
How to report
Email security@angyal.in with “security” in the subject line. We acknowledge every report within 1–2 business days. If you want a reply you can verify came from us, say so and we will agree a channel with you.
A report is most useful to us when it includes:
- what the issue is, and what an attacker could do with it
- where it is — the URL, or the app, its version and the platform you saw it on
- the steps to reproduce it, in enough detail that we can follow them
- whether you intend to publish, and roughly when
What is in scope
- The website at https://angyal.in and everything served under it.
- The mobile apps we publish on Google Play and the Apple App Store — currently Merge and Orbyx.
Out of scope, because they are not ours to fix:
- Google Play, the Apple App Store, and the operating systems the apps run on.
- Google AdMob and the ad content it serves. Report those to Google.
- Anything requiring a rooted or jailbroken device, a modified build of one of our apps, or physical access to a device that is already unlocked.
- Findings from an automated scanner with no demonstrated impact, and reports that a best-practice header or setting is absent without a working attack behind it.
What we ask of you
- Do not access, modify or delete data belonging to anyone else. If you reach someone's data, stop and tell us.
- Do not degrade the service — no denial-of-service testing, no load or stress testing, no spam.
- No social engineering, phishing, or physical attacks against us or anyone connected to us.
- Give us a reasonable chance to fix the issue before you publish. Ninety days is the norm; if we need longer we will say so and explain why, and if we fix it sooner we will tell you.
- Keep to the minimum access needed to demonstrate the problem, and delete anything you retrieved once you have reported it.
What we commit to
- We acknowledge within 1–2 business days and tell you whether we consider the report in scope.
- We keep you updated while we work on it, and tell you when it is fixed.
- We credit you by name in the fix announcement if you want the credit, and we say nothing about you if you do not.
- We will not pursue or support legal action against you for research carried out in good faith within the rules on this page, and we will not report you to law enforcement for it.
We do not run a bug bounty and there is no monetary reward. Saying so plainly is fairer than leaving you to find out after the work is done.
What our attack surface actually is
This is worth knowing before you spend time on it. The website has no accounts, no login, no database and no user-submitted content — the contact form composes a message in your own email app and posts nothing to us. There is no analytics, no advertising and no third-party script on any page.
The apps hold their data on the device and have no server of ours to talk to. Merge and Orbyx have no accounts and no user-to-user communication; the one component that makes network requests is the Google AdMob SDK inside Orbyx. Each app's own privacy policy describes exactly what it stores and transmits.
None of that means there is nothing to find. It does mean the classes of bug worth looking for are narrower than the surface of a typical site, and we would rather tell you than waste your time.
Machine-readable contact
The same contact details are published at /.well-known/security.txt, in the format defined by RFC 9116.
