Policies

Responsible Disclosure

If you have found a security vulnerability on this site, we want to hear about it. Here is how to tell us, and what we promise in return.

Last updated: 31 August 2026

How to report

Email r9harmonyfarm@gmail.com with “Security” in the subject line. Please include enough for us to reproduce the issue: the URL or endpoint, the steps you took, what you expected and what actually happened, and a proof of concept if you have one. Screenshots help.

Please report privately and give us a reasonable chance to fix the issue before discussing it publicly. We ask for 90 days as a default, and will usually be finished long before that.

Our commitment to you

If you act in good faith and follow this policy, we will not pursue or support legal action against you for your research, and we will not treat it as a breach of our Acceptable Use Policy. We will:

  • Acknowledge your report — realistically within 5 working days, since a farm resort has no on-call security team.
  • Tell you whether we have been able to reproduce it, and what we intend to do.
  • Keep you updated while we work on a fix, and let you know when it is deployed.
  • Credit you publicly if you would like that, or keep you anonymous if you would prefer.

We do not operate a paid bug bounty. We would rather say that plainly than imply a reward we have no process to pay.

In scope

  • arnavharmonyfarm.in and its subdomains.
  • The booking flow, guest accounts and the sign-in and password-recovery pages.
  • Our server-side booking and payment functions.
  • Anything exposing another guest’s personal data, or letting one account act as another.

Out of scope

These are either not ours to fix or not, in our judgement, worth a report:

  • Razorpay, Supabase and Vercel’s own infrastructure — report those to them directly; we will happily help you route it.
  • Findings from an automated scanner with no demonstrated impact.
  • Missing security headers, cookie flags or TLS configuration preferences with no working exploit.
  • Email configuration issues (SPF, DKIM, DMARC) absent a demonstrated spoofing attack.
  • Social engineering of our staff or guests, and physical attacks on the property.
  • Anything requiring a rooted device, a browser extension, or an already-compromised account.
  • Rate limiting or brute force on forms without a demonstrated consequence.

Ground rules for testing

The site is a live business taking real bookings from real guests. Please:

  • Use your own account and your own test bookings. Never access, modify or store another guest’s data — if you stumble on someone else’s information, stop, do not save it, and tell us what you saw.
  • Do not run denial-of-service, load or stress tests.
  • Do not send bulk automated traffic that would degrade the site for guests.
  • Do not make real payments to test, and never place bookings you will not cancel.
  • Do not modify or delete data that is not yours.

Testing that damages the service or exposes guest data falls outside this policy and outside the safe harbour above.


Contact us

Arnav Harmony Farm
At Bharje, Pali, sudhagad, 410205, Maharashtra
Phone: +91 8483032662 / +91 8483092662
Email: r9harmonyfarm@gmail.com

All policies