Patrata

Security and Vulnerability Disclosure

Version 2.0 · Effective 7 September 2026 · Patrata is operated by CredSetu Technologies Private Limited (CIN: U62090ME2026PTC475450)

We hold merchants’ financial records. If you have found a way to reach data you should not be able to reach, we want to hear from you before anyone else does. This page tells you how to tell us, and what we promise in return.

1. How to report

Emailinfo@credsetu.in with “Security” in the subject line
Phone+91 79959 53111, if it is serious and you want us moving immediately
Please includeWhat you found, where, and the steps to reproduce it. A screenshot or a short recording helps more than a long description.

You do not need to prove who you are, and you may report anonymously.

2. What we promise

We willWithin
Acknowledge your report, from a person1 working day
Tell you whether we can reproduce it, and how serious we think it is5 working days
Tell you when it is fixedAs soon as it is
Credit you by name, if you want to be creditedOn the fix
Safe harbour. If you report in good faith, follow this page, and do not access, change, keep or share anyone else’s data, we will not pursue any legal action against you and we will not report you to anyone. We will treat you as someone who helped. This holds even if you found it by accident and even if you are a competitor.

3. What is in scope

  • The Patrata mobile application.
  • credsetu.in and anything served from it.
  • Our backend systems and APIs.

4. What we ask you not to do

  • Do not access, download, change or keep anyone else’s data. If you can prove a flaw with one record of your own, stop there. If you accidentally see someone else’s, stop, do not save it, and tell us what you saw so we can assess the exposure.
  • Do not run denial-of-service or load tests. We are a small company on modest infrastructure and you will take the service down for real merchants.
  • Do not use social engineering against our staff, our merchants or their customers.
  • Do not enter anyone’s physical premises.
  • Do not publish the flaw before we have fixed it. Ask us for a timeline; if you think we are being slow, say so and we will explain rather than stall.

5. What we cannot offer

We are a two-person company and we do not pay a bounty. We say so plainly rather than let you spend a weekend on this expecting one. What we can offer is a fast, honest response from a founder, public credit if you want it, and the knowledge that a shopkeeper in Buldhana did not lose his records.

6. If you are a merchant or a customer, not a researcher

If something about your own account looks wrong — data you do not recognise, someone else’s information visible to you, a message you did not expect — that is worth reporting too, and you do not need any technical knowledge to do it. Call +91 79959 53111 or write to info@credsetu.in. You will not be blamed, and you will not be charged.