For everyone
Security & Responsible Disclosure
Effective · Scripteco Technologies Private Limited
How we protect data
- Encryption: HTTPS everywhere, and encryption at rest with our database and storage providers.
- Isolation: database-level rules ensure each organisation sees only its own data. Public campaign pages can only use narrowly scoped functions.
- Answers: in client-scoring mode, correct answers reach the browser only as one-way hashes, never in plain form.
- Access: one-time email links or hashed passwords, and least-privilege roles. Staff see contact details masked by default, and every reveal, export and deletion is logged with a reason.
- Infrastructure: hosted with providers that hold recognised security certifications. Includes protection against attacks and bots, regular backups, and dependency updates.
- People: staff with data access are bound by confidentiality and trained on data handling.
Incidents
We have an incident-response process. If a personal data breach occurs, we will:
- report it to CERT-In within the time it requires (currently 6 hours)
- inform the Data Protection Board of India and affected people as DPDP law requires
- notify affected organisations within 24 hours of becoming aware
Reporting a vulnerability
If you find a security issue, email security@askofy.com with the steps to reproduce it. Please:
- give us reasonable time to fix it before telling anyone else
- do not access, change or delete other people's data. Use only test accounts and data you own
- do not run denial-of-service, spam or social-engineering tests
We will acknowledge your report within 3 working days, keep you updated, and credit you if you wish. We will not take legal action against good-faith research that follows these rules.
Scripteco Technologies Private Limited · Mumbai, Maharashtra, India