CreditBucket Technologies Private Limited is ISO/IEC 27001:2022 certified for Information Security Management. We take the security of our platform, our partners' data, and our borrowers' information seriously, and welcome responsible reporting of genuine security concerns from the security research community.
This policy applies to security vulnerabilities affecting CreditBucket's public-facing digital properties, including this website and associated CreditBucket and Samriddh Kendra digital platforms. It does not extend to social engineering of our staff or partners, physical security of our offices or Samriddh Kendra outlets, or third-party services we integrate with but do not control.
If you believe you've identified a genuine security vulnerability, please report it to info@creditbucket.in with the subject line "Security Disclosure," including:
We will acknowledge genuine reports, investigate promptly, and keep you informed of our progress. As a growing company, we do not currently operate a paid bug bounty program, but we're genuinely grateful for responsible disclosure and will credit researchers who report valid issues, where they'd like to be credited.