Legal
Security Policy
Effective date: 1 January 2025
SR Professional Audio takes the security of our website and the data we handle seriously. This page describes our security practices and how to report a vulnerability responsibly.
How we secure this website
• All traffic is served over HTTPS with TLS 1.2 or higher
• The admin panel is protected by Supabase authentication (JWT-based, secure, httpOnly cookies)
• Row-level security (RLS) is enforced at the database level — public users can only read published content
• API routes that modify data require admin authentication and validate session tokens on every request
• Environment variables (API keys, database credentials) are never exposed to the client or public repositories
• The site is deployed on Vercel, which manages DDoS mitigation and infrastructure security
• Input validation is applied to all form submissions and API endpoints
• Rate limiting is applied to admin login attempts to prevent brute-force attacks
Data we hold
We hold a limited amount of data:
• Product catalogue, component listings, and site settings stored in a Supabase (PostgreSQL) database
• Enquiries are sent directly to WhatsApp from your device — we do not receive or store enquiry submissions on our servers
• Admin account credentials (hashed by Supabase Auth — we never store plaintext passwords)
We do not store payment card data. We do not process financial transactions through this website.
Responsible disclosure
If you discover a security vulnerability on this website, please disclose it to us privately before making it public. We follow a coordinated disclosure approach:
1. Email your findings to srprofessionalaudio@gmail.com with the subject line "Security Disclosure"
2. Include a description of the issue, steps to reproduce, and potential impact
3. We will acknowledge your report within 3 working days
4. We will keep you informed as we investigate and address the issue
5. We will not take legal action against researchers who disclose in good faith
Please do not access, modify, or delete data that does not belong to you. Do not perform destructive tests or attempt to disrupt service availability.
Scope
In scope:
• srprofessionalaudio.in and all subdomains
• The admin panel at srprofessionalaudio.in/admin
Out of scope:
• Third-party services (Supabase, Vercel, WhatsApp) — report those issues to their respective security teams
• Social engineering attacks against our staff
Contact
Security issues: srprofessionalaudio@gmail.com (subject: "Security Disclosure")
General enquiries: srprofessionalaudio@gmail.com
Phone: +91 93947 53929