Vulnerability Disclosure Program
Attendo values the security of our systems and the responsible disclosure efforts of the security research community.
- 1Report
- 2Triage
- 3Coordinate
- 4Fix
Found a security issue? Tell us responsibly.
If you believe you have identified a security vulnerability affecting Attendo systems or applications, we encourage you to report it through our coordinated vulnerability disclosure process. We read every report, and we will tell you what we found.
Safe Harbour
Attendo supports good-faith security research conducted in accordance with this policy. We will not pursue legal action against researchers who:
- 01
Act in good faith.
- 02
Avoid privacy violations and service disruption.
- 03
Do not access or modify customer data unnecessarily.
- 04
Give us reasonable time to investigate and remediate what you report.
If you believe your testing may exceed these guidelines,tell us through the submission formbefore you proceed.
Reporting Guidelines
A clear, complete report helps our team verify and remediate faster — and keeps you clear of any suggestion of misuse.
Please provide
- A clear description of the vulnerability
- Steps to reproduce it
- An assessment of the impact
- Supporting evidence — logs, requests, screenshots
- The affected URLs or assets
Please avoid
- Denial-of-service testing
- Spam or automated scanner floods
- Social engineering of our staff or customers
- Accessing customer data beyond what proves the issue
- Destructive testing — deleting or corrupting data
- Automated exploitation at scale
Scope
This programme applies to production systems and services operated for Attendo, formerly Petpooja Payroll.
In Scope
- attendohr.comThe production marketing site
- payroll.petpooja.comThe Attendo web application
- Attendo production APIsEndpoints serving the live product
- Attendo mobile appsAdmin, Employee and Face Recognition
- Attendo attendance devicesBiometric and face-recognition hardware
- Attendo production infrastructurePublicly reachable, operated for Attendo
Out of Scope
Environments
- Staging, development, QA, testing or temporary environments
- Any pre-production or internal-only host
Assets & activities
- Petpooja Group systems not listed in scope above
- Third-party services and integrations Attendo does not operate
- Social engineering and phishing
- Physical attacks on offices, staff or devices
- Denial-of-service testing
Out-of-Scope Vulnerabilities
Reports limited to the following classes are typically closed as informative. A working proof of concept that demonstrates real impact may still qualify.
- Broken link hijacking (low severity)
- Google Maps API key exposure
- Clickjacking on pages without sensitive actions
- CSRF on unauthenticated or non-sensitive actions
- Attacks requiring MITM or physical device access
- Known vulnerable libraries without a working Proof of Concept
- CSV injection without demonstrated impact
- SSL/TLS best-practice issues
- Missing or weak Content Security Policy configurations
- Missing HttpOnly or Secure cookie flags
- Email configuration issues (SPF, DKIM, DMARC)
- Rate-limiting or brute-force concerns
- CDN cache invalidation or asset expiry issues
- Software version disclosure, banners, verbose errors
- Tabnabbing
- Open redirects without additional exploitability
- Self-XSS
- Promo code or referral abuse
- Access to publicly available user information
- Username or email enumeration
- Third-party platform warnings (e.g. hosting providers, CMS platforms)
- Issues affecting outdated or unsupported browsers (more than two versions behind)
Disclosure Policy
Public disclosure of vulnerabilities is not permitted without explicit written authorisation from Attendo.
Coordinating disclosure protects our customers while a fix is rolled out. Please wait for our written go-ahead before publishing any details — blog posts, talks or social media included.
Submit a Report
Reports are handled confidentially through Bugcrowd, our coordinated disclosure platform.
The form opens right here on this page. Every report is acknowledged.

