Vulnerability Disclosure Policy

Effective Date: January 1, 2026

Delta Pharmacy handles health information, and we take its security seriously. We welcome good-faith reports from security researchers and will never take legal action against anyone who follows this policy honestly.

1. Scope

In scope:

  • deltapharmacy.pk and its subdomains
  • Our order, prescription upload, and account systems

Out of scope:

  • Third-party services we use, such as payment gateways, courier tracking systems, and hosting providers. Report issues directly to the vendor.
  • Denial-of-service or volumetric attacks.
  • Social engineering of our staff, riders, or customers.
  • Physical attacks on our premises.
  • Spam, SPF/DKIM/DMARC configuration reports without a demonstrated exploit, clickjacking on pages with no sensitive action, and other low-impact findings without a realistic attack scenario.

2. Rules of engagement

  • Do not access, download, or modify other people’s data. If you encounter personal or prescription data while testing, stop, take the minimum evidence needed (for example, a redacted screenshot), and report immediately.
  • Do not degrade the service for real customers.
  • Use test accounts and test orders wherever possible. Do not complete fraudulent purchases.
  • Give us reasonable time to fix an issue before any public disclosure (see section 4).

3. How to report

Email security@deltapharmacy.pk with:

  • A description of the vulnerability and its impact
  • Steps to reproduce, such as URLs, request and response samples, and screenshots
  • Your name or handle, if you would like public credit

Reports in English or Urdu are both welcome.

4. What you can expect from us

  • Acknowledgement within 3 working days of your report.
  • An assessment and an expected fix timeline within 10 working days.
  • Critical issues affecting customer or prescription data are treated as emergencies and prioritized above all other work.
  • We will keep you informed, credit you on this page (with your permission) once the issue is fixed, and never pursue legal action for good-faith research conducted under this policy.
  • We do not currently run a paid bug bounty, but we may send a token of thanks for significant findings.

5. Safe harbor

Security research conducted in genuine good faith and in line with this policy is authorized activity. We will not initiate legal action for such research. If a third party does, we will make it known that your actions were authorized under this policy.

Log in

You dont have an account yet? Register Now

Delivery to you

Add an exact address, a convenient pick-up point or a parcel locker to see the conditions for delivery of goods in advances.

Search

Your Cart

Add 9,999.00 to cart and get free shipping!

No products in the cart.

You dont have any products in your cart yet, add a few products to experience this experience.

Recently Removed Products