Security & Vulnerability Disclosure
Operated by Ebenworks Systems (Pvt) Ltd · accounts.ebstar.co · Last updated 22 July 2026
Ebenworks Accounts is the single sign-on, subscription and billing system for the whole Ebenworks product family, so we take its security seriously. If you believe you have found a security vulnerability in accounts.ebstar.co or any Ebenworks service, we want to hear from you.
How to report
Email security@ebstar.co with enough detail to reproduce the issue: the affected URL or endpoint, a description of the vulnerability, step-by-step reproduction, and its potential impact. Please report promptly and give us reasonable time to investigate and remediate before any public disclosure.
A machine-readable version of this policy is published at /.well-known/security.txt (RFC 9116).
Our commitment (safe harbour)
If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly. We aim to acknowledge reports within 3 business days and to keep you updated as we work toward a fix.
Please do
- Report as soon as you discover a potential issue.
- Use only your own accounts or test accounts, and only interact with data you own.
- Stop and report immediately if you encounter personal data belonging to others.
- Keep the details of any vulnerability confidential until we confirm it is resolved.
Out of scope
The following are not eligible and should not be attempted:
- Denial-of-service (DoS/DDoS), volumetric or resource-exhaustion testing.
- Social engineering, phishing, or physical attacks against our staff, partners or facilities.
- Automated scanning that degrades service, or testing against real users’ accounts/data.
- Reports from automated tools without a demonstrated, exploitable impact.
- Missing best-practice headers, or issues in third-party services we do not control (report those to the provider).
Recognition
We do not currently run a paid bug-bounty programme, but we are grateful for responsible disclosure and are happy to credit researchers who report valid, previously-unknown issues (with your permission).
Security reports: security@ebstar.co · General privacy matters: privacy@ebstar.co.
Privacy · Terms · Acceptable Use · Refunds · Sub-processors · Security · Sign in
Privacy requests: privacy@ebstar.co · Legal: legal@ebstar.co