Back to BookPGnow

Responsible disclosure

Help us keep every booking safe.

Found a genuine security weakness? Report it privately. We will acknowledge useful, good-faith research and keep you informed through remediation.Report securely

How to report

A clear report helps us act quickly.

  1. 01
    Describe the vulnerability

    Include the affected URL or app screen, impact, and the minimum steps needed to reproduce it.

  2. 02
    Share evidence safely

    Use redacted screenshots, request IDs, and a proof of concept that does not expose real customer data.

  3. 03
    Wait for coordination

    We will acknowledge the report, validate it, and coordinate remediation and recognition with you.

Testing scope

Where research is welcome.

bookpgnow.in and its authenticated customer flows

owner.bookpgnow.in property operations

provider.bookpgnow.in service-provider workflows

BookPGnow Android applications and public APIs

Safe-harbor rules

Protect people while testing.

Use only accounts and records you own or have explicit permission to test.

Stop immediately if you encounter personal data, payment data, or another user’s account.

Do not disrupt availability, send spam, use social engineering, or perform physical attacks.

Give us reasonable time to investigate and fix the issue before public disclosure.

Not eligible

Reports must show meaningful security impact.

Automated scanner output without validation, missing headers without an exploit, clickjacking on non-sensitive pages, rate-limit observations without impact, self-XSS, outdated browser issues, spam, and reports that require social engineering or physical access are generally not eligible.

Hall of Fame

Researchers who made BookPGnow safer.

Recognition begins with the first validated disclosure.

With the researcher’s consent, validated contributors may be listed here by name or handle after remediation. Reward eligibility and amount depend on severity, evidence quality, and business impact; no payment is guaranteed before written confirmation.

Security contact

Send the details privately.

Do not include passwords, full payment data, government IDs, or unnecessary personal information.

[email protected]