Last edited: 24 July 2026
Anuma holds catalogs, rate cards, and conversations that businesses depend on. If you find a way to break that trust, we want to hear it from you first, and we will treat you as a colleague, not a threat.
Email security@anuma.co.in with what you found, the steps to reproduce it, and the impact you believe it has. Proof-of-concept material helps; screenshots and request traces are usually enough. We acknowledge every report within 48 hours, give you a triage verdict within 7 days, and keep you posted until the issue is resolved.
In scope: anuma.co.in and its subdomains, the Anuma merchant and admin applications, our APIs, and the voice and messaging intake surfaces we operate, including prompt-injection and policy-bypass attacks against our agent functions (for example, making the negotiation agent cross a configured floor). Out of scope: third-party platforms we build on (Meta, payment gateways, cloud providers), findings that require stolen credentials, and reports from automated scanners with no demonstrated impact.
Give us 90 days from acknowledgement before publishing, and longer only if we agree it is needed for a fix that protects merchants. We are happy to coordinate the writeup and the timeline with you.