Last updated: June 13, 2026
Security Policy
PARKLIFY PRIVATE LIMITED (trading as Limurse) takes reasonable measures to protect Limurse users, creator marketing data, and payment workflows. This policy describes how to report security issues and our responsible disclosure approach.
Report a vulnerability
If you believe you have found a security issue, report it promptly:
- Email: apps@limurse.ai with subject line "Security Report"
- Include steps to reproduce, impact assessment, and optional proof-of-concept
- Do not publicly disclose before we have had reasonable time to investigate and remediate
- PGP encryption is available on request for sensitive reports
Scope
In scope
- limurse.ai web application and authenticated APIs
- Mobile applications distributed by Limurse
- Authentication, authorization, and session handling
- Data exposure, injection, or access-control flaws in our code
Out of scope
- Third-party services (Cashfree, PayPal, social networks, email providers)
- Social engineering, phishing, or physical attacks
- Denial-of-service or load tests without written approval
- Issues in outdated browsers or unsupported client configurations
- Accessing or modifying other users' data without authorization
Responsible disclosure
- We aim to acknowledge reports within 2 business days
- We validate, prioritize, and remediate confirmed issues
- We may request additional information to reproduce the finding
- We coordinate public disclosure timing with reporters when appropriate
- We may acknowledge researchers with permission
Security practices
Infrastructure
- TLS encryption for data in transit
- Cloud hosting with access controls and monitoring
- Secrets management and least-privilege administrative access
- Backups and incident response procedures
Application
- Authentication and role-based access for brands, creators, and admins
- Input validation, CSRF protections, and secure session handling
- Dependency and vulnerability monitoring
- Content security policies and security headers where applicable
Payments
- Card and UPI credentials are collected on Cashfree or PayPal hosted pages
- Limurse does not store full payment credentials on its servers
Contact
Security: apps@limurse.ai
Data protection contact: Akshat Tiwari
Phone: +91 9650816243
Address: A1-402, Krishna Apra Gardens, Ghaziabad, Uttar Pradesh 201014, India
Frequently asked questions
How do I report a security vulnerability?
Email apps@limurse.ai with subject line "Security Report", steps to reproduce, and impact details. Do not publicly disclose before we have had time to remediate.
What security measures does Limurse use?
TLS in transit, access controls, secure authentication, hosted payment pages via Cashfree and PayPal, monitoring, and responsible disclosure procedures.