Help us keep Fininvo safe. How to report a vulnerability, the response times you can expect, and our safe-harbour commitment.
July 2, 2026
August 1, 2026
3.0
This document is published by Fininvo, a trade name of Prashbi Global Services Pvt. Ltd., a company incorporated under the laws of India (CIN: U52100KA2020PTC133490), with its registered office at Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India. References to "Fininvo", "we", "us", or "our" in this document refer to Prashbi Global Services Pvt. Ltd..
We value the work of security researchers and the broader community in keeping Fininvo and our customers safe. If you discover a vulnerability, we ask you to report it to us privately so we can fix it before it is disclosed publicly. We commit to responding quickly, keeping you informed, and never taking legal action against good-faith research conducted under this policy.
Email security@fininvo.com with a clear description of the issue, the steps to reproduce it, the affected URL or feature, the potential impact as you understand it, and any supporting evidence (requests, responses, screenshots). This address is also published in our /.well-known/security.txt file. If the report contains sensitive proof-of-concept data, say so and we will arrange a secure channel.
| Milestone | Target |
|---|---|
| Acknowledgement of your report | Within 3 business days |
| Initial triage and severity assessment | Within 7 business days |
| Status updates while we remediate | At least every 14 days |
| Remediation of confirmed critical issues | Mitigation within 72 hours of confirmation |
| Notification to you when fixed | On deployment of the fix |
The following are generally not accepted unless you demonstrate a concrete exploit path:
We support coordinated disclosure: once a fix is deployed and verified, we are happy to agree a public disclosure date with you, normally no earlier than 90 days from your report or 30 days after the fix, whichever comes first. Please do not disclose before an agreed date; if we are unresponsive past our SLAs, a reminder to security@fininvo.com referencing this policy will escalate the report.
If you make a good-faith effort to comply with this policy, we will treat your research as authorised under the Terms of Service and Acceptable Use Policy, will not pursue legal action against you for it (including under the Information Technology Act), and will work with you to understand and resolve the issue quickly. If legal action is initiated by a third party against you for activities conducted under this policy, we will make it known that your actions were authorised. This safe harbour does not apply to research that violates the guidelines above or the law.
We do not currently operate a paid bug bounty programme. With your permission, we credit meaningful reports with a public acknowledgement, and we may offer discretionary thanks for exceptional findings. If we launch a paid programme, it will be announced on this page.
Security Team
security@fininvo.comRegistered Office
Prashbi Global Services Pvt. Ltd.
Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony,
R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India
CIN: U52100KA2020PTC133490