Responsible disclosure
Help us keep CardMasters safe
If you believe you found a security or privacy issue, email hello@cardmasters.in. Include the affected URL, impact, reproducible steps and the smallest safe proof needed to explain the issue.
Safe-testing boundaries
- Use only accounts and data you own or have explicit permission to test.
- Do not access, retain, alter or disclose another person's data.
- Do not use denial-of-service, spam, social engineering, credential attacks or destructive testing.
- Stop when you have enough evidence to report the issue safely.
What to expect
We aim to acknowledge a complete report within three business days, investigate proportionately and keep the reporter informed when practical. CardMasters does not currently operate a paid bug-bounty program, and a report does not create an entitlement to payment or public credit.
Privacy-sensitive reports
Do not email card numbers, bank credentials, statement rows, passwords or identity documents. Redact personal information and use synthetic examples wherever possible. For ordinary support or data-rights requests, use the contact page or read the privacy policy.