We take the security of RestoPOS seriously. If you've discovered a vulnerability, we want to hear from you — responsibly. Help us protect our users.
Effective Date: 29 June 2026 | Response SLA: 72 hours acknowledgement
TechSlide IT Solutions Pvt Ltd, the developer and operator of RestoPOS, is committed to maintaining the security and integrity of our platform and the data entrusted to us by thousands of restaurant operators across India. Security is not an afterthought — it is a foundational element of how we build and operate our software.
We recognise that despite our best efforts, no software system is entirely free of vulnerabilities. The security research community plays a valuable role in identifying weaknesses that internal teams may miss. We are grateful to researchers who responsibly disclose security issues and are committed to working collaboratively to resolve confirmed vulnerabilities.
This Responsible Disclosure Policy outlines the framework for researchers and users to report security vulnerabilities to us, the process we follow to address such reports, and the protections we extend to good-faith reporters.
The following systems and vulnerability types are within scope for responsible disclosure:
The following are explicitly out of scope and should not be tested or reported:
Testing activities must not disrupt service availability, access other users' data, or violate applicable law. Any testing must be performed only on your own test account.
Please report security vulnerabilities through one of the following channels:
Please do not report security vulnerabilities through public channels such as GitHub Issues, social media, public forums, or support tickets. Public disclosure before we have had a reasonable opportunity to investigate and remediate puts our users at risk.
Do not disclose any vulnerability or your testing activity to any third party before we have confirmed that the issue is resolved, or until we have agreed on a disclosure timeline with you.
To help us triage and investigate your report efficiently, please include the following information:
Incomplete reports may result in delayed response. The more detail you provide, the faster we can triage and act.
We are committed to the following response timeline for all reports received at security@restopos.in or through the form below:
Fix timelines may vary based on severity and complexity. Complex issues may require longer remediation periods. We will communicate any delays transparently. We do not currently operate a paid bug bounty programme, but we sincerely appreciate responsible reporters and will acknowledge your contribution.
TechSlide IT Solutions Pvt Ltd extends the following safe harbor protections to security researchers who report vulnerabilities in good faith and in accordance with this policy:
Safe harbor does not apply if you:
Researchers who violate these conditions may be subject to legal action under the IT Act, 2000, and other applicable Indian laws.
While we take every reasonable and practicable step to secure our infrastructure and your data, TechSlide IT Solutions Pvt Ltd is not responsible for security incidents arising from events beyond our reasonable control. This includes, but is not limited to:
Our server infrastructure is maintained with industry-standard security practices. However, absolute security cannot be guaranteed for any internet-connected system. Users are advised to use strong passwords, enable two-factor authentication where available, and report any suspicious activity promptly.
Use the form below to submit a structured vulnerability report. All submissions are treated as confidential and reviewed by our security team.
All fields marked * are required. We will acknowledge your submission within 72 hours.
Join 500+ restaurants already using RestoPOS. Setup takes 10 minutes.
👋 Welcome! Let's get started
Fill in your details to start chatting with our assistant.