For everyone

Security & Responsible Disclosure

Effective · Scripteco Technologies Private Limited

How we protect data

  • Encryption: HTTPS everywhere, and encryption at rest with our database and storage providers.
  • Isolation: database-level rules ensure each organisation sees only its own data. Public campaign pages can only use narrowly scoped functions.
  • Answers: in client-scoring mode, correct answers reach the browser only as one-way hashes, never in plain form.
  • Access: one-time email links or hashed passwords, and least-privilege roles. Staff see contact details masked by default, and every reveal, export and deletion is logged with a reason.
  • Infrastructure: hosted with providers that hold recognised security certifications. Includes protection against attacks and bots, regular backups, and dependency updates.
  • People: staff with data access are bound by confidentiality and trained on data handling.

Incidents

We have an incident-response process. If a personal data breach occurs, we will:

  • report it to CERT-In within the time it requires (currently 6 hours)
  • inform the Data Protection Board of India and affected people as DPDP law requires
  • notify affected organisations within 24 hours of becoming aware

Reporting a vulnerability

If you find a security issue, email security@askofy.com with the steps to reproduce it. Please:

  • give us reasonable time to fix it before telling anyone else
  • do not access, change or delete other people's data. Use only test accounts and data you own
  • do not run denial-of-service, spam or social-engineering tests

We will acknowledge your report within 3 working days, keep you updated, and credit you if you wish. We will not take legal action against good-faith research that follows these rules.

Scripteco Technologies Private Limited · Mumbai, Maharashtra, India