Attendoformerly Petpooja Payroll
Trust & Security

Vulnerability Disclosure Program

Attendo values the security of our systems and the responsible disclosure efforts of the security research community.

  1. 1Report
  2. 2Triage
  3. 3Coordinate
  4. 4Fix

Found a security issue? Tell us responsibly.

If you believe you have identified a security vulnerability affecting Attendo systems or applications, we encourage you to report it through our coordinated vulnerability disclosure process. We read every report, and we will tell you what we found.

Our commitment

Safe Harbour

Attendo supports good-faith security research conducted in accordance with this policy. We will not pursue legal action against researchers who:

  1. 01

    Act in good faith.

  2. 02

    Avoid privacy violations and service disruption.

  3. 03

    Do not access or modify customer data unnecessarily.

  4. 04

    Give us reasonable time to investigate and remediate what you report.

If you believe your testing may exceed these guidelines,tell us through the submission formbefore you proceed.

How to report

Reporting Guidelines

A clear, complete report helps our team verify and remediate faster — and keeps you clear of any suggestion of misuse.

Please provide

  • A clear description of the vulnerability
  • Steps to reproduce it
  • An assessment of the impact
  • Supporting evidence — logs, requests, screenshots
  • The affected URLs or assets

Please avoid

  • Denial-of-service testing
  • Spam or automated scanner floods
  • Social engineering of our staff or customers
  • Accessing customer data beyond what proves the issue
  • Destructive testing — deleting or corrupting data
  • Automated exploitation at scale
What we cover

Scope

This programme applies to production systems and services operated for Attendo, formerly Petpooja Payroll.

In Scope

  • attendohr.comThe production marketing site
  • payroll.petpooja.comThe Attendo web application
  • Attendo production APIsEndpoints serving the live product
  • Attendo mobile appsAdmin, Employee and Face Recognition
  • Attendo attendance devicesBiometric and face-recognition hardware
  • Attendo production infrastructurePublicly reachable, operated for Attendo

Out of Scope

Environments

  • Staging, development, QA, testing or temporary environments
  • Any pre-production or internal-only host

Assets & activities

  • Petpooja Group systems not listed in scope above
  • Third-party services and integrations Attendo does not operate
  • Social engineering and phishing
  • Physical attacks on offices, staff or devices
  • Denial-of-service testing
Known ineligible

Out-of-Scope Vulnerabilities

Reports limited to the following classes are typically closed as informative. A working proof of concept that demonstrates real impact may still qualify.

  • Broken link hijacking (low severity)
  • Google Maps API key exposure
  • Clickjacking on pages without sensitive actions
  • CSRF on unauthenticated or non-sensitive actions
  • Attacks requiring MITM or physical device access
  • Known vulnerable libraries without a working Proof of Concept
  • CSV injection without demonstrated impact
  • SSL/TLS best-practice issues
  • Missing or weak Content Security Policy configurations
  • Missing HttpOnly or Secure cookie flags
  • Email configuration issues (SPF, DKIM, DMARC)
  • Rate-limiting or brute-force concerns
  • CDN cache invalidation or asset expiry issues
  • Software version disclosure, banners, verbose errors
  • Tabnabbing
  • Open redirects without additional exploitability
  • Self-XSS
  • Promo code or referral abuse
  • Access to publicly available user information
  • Username or email enumeration
  • Third-party platform warnings (e.g. hosting providers, CMS platforms)
  • Issues affecting outdated or unsupported browsers (more than two versions behind)
Important

Disclosure Policy

Public disclosure of vulnerabilities is not permitted without explicit written authorisation from Attendo.

Coordinating disclosure protects our customers while a fix is rolled out. Please wait for our written go-ahead before publishing any details — blog posts, talks or social media included.

Need authorisation?Ask in your report

Submit a Report

Reports are handled confidentially through Bugcrowd, our coordinated disclosure platform.

The form opens right here on this page. Every report is acknowledged.

Submit a Vulnerability Report

Loading the secure submission form…

Form not loading?Open it on Bugcrowd