This policy document is a structured drafting placeholder established for architectural, regulatory, and UX integrity. It does not constitute final binding legal terms. Formal legal review and jurisdiction-specific counsel are required before official commercial deployment.
We welcome contributions from independent security researchers to maintain the resilience of the Food Tailor platform. We commit to working collaboratively with researchers who conduct testing in good faith.
Food Tailor will not pursue legal action against researchers who:
• Do not disrupt user service, degrade performance, or access private customer data without authorization.
• Avoid executing Denial of Service (DoS/DDoS) attacks, social engineering, or physical intrusion into partner kitchens.
• Provide adequate time for remediation before publishing details publicly.
• In Scope: *.foodtailor.in web application endpoints, customer authentication flows, and public REST APIs.
• Out of Scope: Third-party payment gateways (Razorpay), physical security, partner kitchen networks, and email spam testing.
Send your vulnerability reports containing detailed reproduction steps and proof-of-concept scripts to security@foodtailor.in. We acknowledge valid submissions within 48 hours.