Security and Responsible Disclosure
Last updated: 2026-07-24
We welcome reports from security researchers and will work with you in good faith to fix issues.
Reporting a vulnerability
Email hello@hidangi.my with enough detail to reproduce the issue. Please give us reasonable time to investigate and fix before any public disclosure.
Please do
When testing, please:
- Test only against your own account and data.
- Avoid privacy violations, service disruption, and destruction of data.
- Report promptly and keep details confidential until a fix ships.
Our commitment
We do not pursue good-faith researchers who follow this policy. There is no paid bug bounty at this time, but we credit reporters who wish to be named.
How we protect data
Guest phone numbers are encrypted at rest with a separate tenant-scoped matching hash; access tokens rotate; and Hidangi holds no food-payment card data because guests pay at the counter.
