Security & Disclosure

Last updated: 15 August 2026

How we protect your account and your data, and how to report a vulnerability to us safely. We welcome good-faith security research.

1. How we protect your data

  • Encryption in transit. All traffic between your device and our servers uses HTTPS/TLS.
  • Encryption at rest. Our database and media storage are encrypted on disk.
  • Password storage. Passwords are stored only as salted hashes. We cannot read your password, and we will never ask you for it.
  • Session security. Sessions use short-lived access tokens in HTTP-only, secure cookies, with refresh tokens rotated on every use. Reuse of an old token is treated as theft and revokes the whole session chain.
  • Request protection. Cross-site request forgery protection on state-changing endpoints, and rate limiting on authentication and upload endpoints.
  • Uploads. Media goes directly from your browser to object storage using short-lived pre-signed URLs. We never execute or unpack uploaded files on our servers.
  • Secrets and access. Credentials live in a managed secrets store, never in code. Access to production data is limited to those who need it.
  • Data location. Your data is stored in Mumbai, India (AWS ap-south-1).

2. What you can do

  • Use a unique password for Kissa, or sign in with Google.
  • Sign out on devices you no longer use — a password change revokes existing sessions.
  • Treat any email asking for your password, an OTP, or payment as fraudulent. We never send those. See Payments & Refunds.

3. Reporting a vulnerability

Email security@kissa.texotic.in. Please include what you found, the steps to reproduce it, its impact, and any proof of concept. We acknowledge reports within 3 working days and will keep you updated while we fix it.

Report privately, and give us reasonable time to fix the issue before you disclose it publicly. We do not currently run a paid bug bounty, but we credit researchers who ask to be credited.

4. Safe harbour

If you research in good faith and follow this policy, we will not pursue legal action against you, and we will say so if a third party asks. Good faith means:

  • you use only your own test accounts, and do not access anyone else’s data;
  • you stop as soon as you have proved the issue exists, and do not download, alter, or retain data that is not yours;
  • you do not degrade the service for others, or destroy data;
  • you do not extort, threaten, or set a deadline as a condition of disclosure.

5. Out of scope

These are not accepted as vulnerabilities and testing them is not authorised:

  • Denial-of-service, volumetric, or load testing of any kind.
  • Social engineering, phishing, or physical attacks against our staff or creators.
  • Automated scanner output submitted without a demonstrated, exploitable impact.
  • Missing security headers, cookie flags, or TLS configuration preferences with no exploitable consequence.
  • Issues in third-party services we do not control — report those to their owners.
  • Vulnerabilities requiring a rooted device, a compromised OS, or physical access.

6. If a breach affects you

If a personal data breach occurs, we will notify the Data Protection Board of India and the affected users as required by the Digital Personal Data Protection Act, 2023, and report to CERT-In within the timelines its directions require. Our notice will tell you what happened, what data was involved, and what you should do.

7. Related

What we collect is set out in the Privacy Policy and summarised in the Data Safety Summary. For anything non-security, use Contact.

Security & Disclosure — Kissa