Vulnerability Disclosure Policy
Effective Date: January 1, 2026
Delta Pharmacy handles health information, and we take its security seriously. We welcome good-faith reports from security researchers and will never take legal action against anyone who follows this policy honestly.
1. Scope
In scope:
- deltapharmacy.pk and its subdomains
- Our order, prescription upload, and account systems
Out of scope:
- Third-party services we use, such as payment gateways, courier tracking systems, and hosting providers. Report issues directly to the vendor.
- Denial-of-service or volumetric attacks.
- Social engineering of our staff, riders, or customers.
- Physical attacks on our premises.
- Spam, SPF/DKIM/DMARC configuration reports without a demonstrated exploit, clickjacking on pages with no sensitive action, and other low-impact findings without a realistic attack scenario.
2. Rules of engagement
- Do not access, download, or modify other people’s data. If you encounter personal or prescription data while testing, stop, take the minimum evidence needed (for example, a redacted screenshot), and report immediately.
- Do not degrade the service for real customers.
- Use test accounts and test orders wherever possible. Do not complete fraudulent purchases.
- Give us reasonable time to fix an issue before any public disclosure (see section 4).
3. How to report
Email security@deltapharmacy.pk with:
- A description of the vulnerability and its impact
- Steps to reproduce, such as URLs, request and response samples, and screenshots
- Your name or handle, if you would like public credit
Reports in English or Urdu are both welcome.
4. What you can expect from us
- Acknowledgement within 3 working days of your report.
- An assessment and an expected fix timeline within 10 working days.
- Critical issues affecting customer or prescription data are treated as emergencies and prioritized above all other work.
- We will keep you informed, credit you on this page (with your permission) once the issue is fixed, and never pursue legal action for good-faith research conducted under this policy.
- We do not currently run a paid bug bounty, but we may send a token of thanks for significant findings.
5. Safe harbor
Security research conducted in genuine good faith and in line with this policy is authorized activity. We will not initiate legal action for such research. If a third party does, we will make it known that your actions were authorized under this policy.




