We welcome reports from security researchers. Report vulnerabilities to security@swiftrail.ai (PGP key available on request) with steps to reproduce. Do not access, modify or exfiltrate data beyond what is necessary to demonstrate the issue; do not perform DoS, social engineering or physical attacks; test only on sandbox where possible. We acknowledge within 3 business days, keep you informed, and do not pursue legal action against good-faith research that complies with this policy. Recognition is at our discretion. Our controls: PCI-DSS compliant infrastructure, ISO 27001-aligned ISMS, periodic CERT-In-empanelled VAPT, encryption, tokenisation, access control, logging and 24×7 monitoring.
Definitions used across our policies
Common definitions used across policies:
- "Company", "we", "us", "our" — Global eServe Technologies LLP, a limited liability partnership incorporated under the Limited Liability Partnership Act, 2008 (LLPIN to be published), having its registered office at Flat No. 201, 2nd Floor, Plot 577, Triveni Apartment, N M Joshi Marg, Byculla (West), Mumbai – 400027, Maharashtra, India, operating the brand and platform SwifTrail.
- "Platform" — the websites swiftrail.ai and swiftrail.in, dashboards, portals, mobile applications, APIs and related services.
- "Merchant" / "Partner" / "Agent" — a business or individual who has entered into an agreement with the Company to use the Platform.
- "End User" — a customer of a Merchant who makes a payment through the Platform.
- "Payment Partners" — RBI-licensed Payment Aggregators, banks (including escrow, sponsor and card-issuing banks), NBFCs, IRDAI-registered insurers, authorised government-scheme channels, card networks, NPCI and other regulated entities through which payment and financial services are facilitated.
