About this website
buyelectrical is an informational website for VendorStocks.
It publishes blogs, manufacturers' price lists and product information, and shares information about the VendorStocks marketplace. Nothing is bought or sold here: accounts, RFQs, orders and payments all live on vendorstocks.com, under VendorStocks' own terms.
Security is foundational to buyelectrical and VendorStocks. The Website is an informational site with no accounts, no forms and no payments, so the most sensitive thing you can do here is follow a link to VendorStocks. This page outlines how we protect the Website, the safeguards that protect you on VendorStocks, and how to report a vulnerability responsibly.
How We Protect This Website
Encrypted in Transit
Every page, price list and image on the Website is served over HTTPS, so what you read is encrypted on its way to you and cannot be altered in transit.
Nothing to Sign In To
The Website has no sign-up, no login, no forms and no payments. There are no passwords on it to steal and no database of visitors to breach.
Static by Design
Every page is built in advance and served as a static file. There is no server-side application, database or admin panel exposed to the internet, which removes the most common routes of attack.
No Third-Party Scripts
Fonts, images and code are served from the Website itself. There are no analytics, advertising or tracking scripts, and every release is checked to make sure no page loads anything from another host.
Safe Links Out
Every link that leaves the Website opens in a new tab, isolated so that the page it opens cannot control or redirect this one.
When You Go to VendorStocks
Buying, selling, RFQs and payments happen on vendorstocks.com, not on the Website. There, VendorStocks applies the safeguards below; VendorStocks Security has the full detail.
SSL / TLS Encryption
All traffic between your browser and VendorStocks is encrypted using TLS 1.3, and data at rest — documents and database records — is encrypted with AES-256. HTTPS is enforced across the platform, with HSTS to prevent protocol downgrade attacks.
Secure Authentication
Accounts are protected with securely hashed credentials, session-based access tokens, and short-lived sessions. Sign-in activity is monitored for anomalies, and passwords are never stored in plain text.
Data Protection
Role-based access control and row-level security isolate every organisation's data. Verification documents are held in access-restricted storage with audit logging, backups are encrypted, and access to production data is limited and monitored.
Vendor Verification
Sellers undergo document-based verification — PAN, GSTIN, and business registration are reviewed before activation. Verification shows that a review was completed; it is not an endorsement, and accounts are re-evaluated periodically.
Fraud Prevention
VendorStocks continuously monitors for fake listings, fraudulent transactions, and coordinated abuse, with automated safeguards, rate limiting and bot defences, and staff who investigate suspicious behaviour.
Payment Security
Payments are processed by PCI-DSS compliant gateway partners (Razorpay / PayU). VendorStocks never stores full card numbers, CVVs, UPI PINs, or net-banking credentials — sensitive payment data is handled entirely by the gateway.
Responsible Disclosure Policy
We welcome reports from security researchers and users who discover potential vulnerabilities in buyelectrical or VendorStocks. Disclosing responsibly keeps other users protected while we resolve the issue.
How to Report
- Email our security team. Send a detailed report to support@skylightsenergy.in with a subject line beginning “Security”. Include steps to reproduce, the affected URLs or endpoints, and any supporting evidence.
- Give us time to investigate. We will acknowledge your report within 3 business days and work to validate and remediate confirmed issues as quickly as possible.
- Disclose responsibly. Please do not publicly disclose the issue, access or modify other users' data, or degrade our service while we investigate. Acting in good faith under this policy will not result in legal action from us.
Please Avoid
- Accessing, downloading, or modifying data that does not belong to you
- Denial-of-service (DoS) testing, spam, or social engineering of our staff or users
- Automated scanning that degrades performance for others
- Publicly disclosing a vulnerability before we have resolved it
Your Role in Staying Secure
- Check where you sign in: buyelectrical never asks for a password, OTP or payment. Sign in only at vendorstocks.com, and check the address bar before you do.
- Protect your credentials: never share your password, and use a strong, unique one.
- Verify before you transact: confirm vendor details and order terms before making payments.
- Report anything suspicious: unexpected emails, messages or listings that use the buyelectrical or VendorStocks name should be reported immediately.
- Keep your device secure: use updated browsers and avoid logging in on untrusted networks or shared devices.
While we apply rigorous safeguards, no system is ever completely immune to risk. We continuously strengthen our defences and rely on our community to help keep the Website and VendorStocks safe.
Security contact
To report a vulnerability or raise a security concern, contact our security team:
- support@skylightsenergy.inSubject: “Security”
- Company
- SKYLIGHTS ENERGY
- Address
- No. 15, 3rd Main, 1st Cross, Begur Road, Bommanahalli, Bengaluru, Karnataka 560068, India