Security & Vulnerability Disclosure Program
Crednip is committed to preserving the confidentiality, integrity, and security of our marketplace. We welcome feedback from security researchers and ethical hackers to help protect our community.
Marketplace Role Disclaimer
Crednip is an online discovery and communication marketplace connecting borrowers and potential lenders independently. Crednip is not a bank, NBFC, or regulated P2P lender. Crednip does not approve loans, underwrite credit, set interest rates or LTV ratios, disburse funds, take custody of collateral, value assets, or guarantee transactions.
Program Scope & Operational Status
Vulnerability Disclosure Program (VDP) Governance
Crednip currently operates a Vulnerability Disclosure Program (VDP), not a paid bug bounty program. Submissions help us maintain security for all users and do not create an entitlement to financial compensation or monetary bounties.
Authorized In-Scope Assets
Security research is authorized strictly against the following verified production assets owned and controlled by Crednip:
Web Application & Marketplace Directory
Mobile Application
Coordinated Disclosure Policy
- Prompt Notification: Inform us as soon as reasonably possible upon discovering a potential security vulnerability.
- Investigation & Remediation: Crednip will acknowledge receipt of your report and work diligently to investigate and resolve valid findings.
- Coordinated Release: Give Crednip a reasonable time period to remediate the issue before making any public disclosure. Public disclosure must be coordinated directly with our team.
- User Protection: Make a sincere effort to avoid violating user privacy, modifying data, or interrupting marketplace functionality during research.
Rules of Engagement
- 1Test only using accounts and data you own or have explicit authorization to test.
- 2Stop testing immediately if you encounter sensitive data belonging to another user.
- 3Access only the minimum information required to demonstrate security impact.
- 4Never modify, delete, exfiltrate, retain, or publicly disclose user information.
- 5Avoid actions that degrade service performance or disrupt active marketplace users.
- 6Do not perform high-volume automated scanning, spamming, or brute-force credential stuffing.
- 7Never attempt persistence, lateral movement, or production database extraction.
- 8Submit findings privately to security@crednip.com and keep details confidential during remediation.
Out-of-Scope Vulnerabilities
The following findings are considered out-of-scope for our VDP and will not be accepted:
Safe Harbor Protection
Crednip will not initiate legal action against security researchers who conduct good-faith security research that complies strictly with this policy, respects user privacy, avoids service disruption, stays within authorized scope, and reports findings privately. Third-party services or infrastructure providers are governed by their own respective terms.
Impact Severity Guide
Remote Code Execution (RCE), Authentication Bypass, SQL Injection, or mass exposure of sensitive financial records.
Privilege Escalation, significant authorization bypass (IDOR), or stored XSS on sensitive user pages.
Limited authorization issues, reflected XSS with demonstrable impact, or scoped information disclosure.
Low-impact security issues with a demonstrable security consequence.
* Final severity classification is determined by Crednip based on demonstrated security impact and exploitability.
Submitting a Security Report
Required Report Information:
Hall of Fame & Acknowledgments
We express our gratitude to security researchers who help keep Crednip safe for everyone. Researchers may opt in to public acknowledgment after a valid finding has been confirmed and remediated.
No security researchers have opted into public acknowledgment yet.
Be among the first ethical researchers recognized on our official Hall of Fame by submitting a valid report.
