Vulnerability Disclosure Policy
Last updated: September 11, 2026
Keeping merchant and customer data safe matters to us, and we welcome reports from security researchers. This policy explains what you may test, how to report what you find, what you can expect from us, and the safe harbor we offer to anyone who follows it in good faith.
How to report
Email security@platformdtc.com. Please include:
- The affected host, URL or feature
- The type of vulnerability
- Step-by-step instructions to reproduce it, including any requests, payloads, screenshots or video
- The impact: what an attacker could do with it
- The accounts or store identifiers you used while testing
- How we can reach you with follow-up questions
One report per vulnerability helps us track and fix each issue. Please include no more personal data about anyone else than you need to demonstrate the issue.
What to expect from us
- We acknowledge every report within 48 hours.
- We will tell you whether we were able to reproduce the issue, and let you know when it has been fixed.
- Please give us a reasonable opportunity to investigate and fix the issue before you disclose it publicly, and coordinate the timing of any disclosure with us.
Scope
In scope
Systems PlatformDTC operates:
- platformdtc.com and www.platformdtc.com — our website and the merchant dashboard
- api.platformdtc.com — the PlatformDTC API, including the Agent Gateway
- checkout.platformdtc.com, and the
/checkout,/cartand/paypaths on platformdtc.com — hosted checkout - accounts.platformdtc.com
- docs.platformdtc.com — developer documentation
- status.platformdtc.com — the status page
- mail.platformdtc.com — webmail
- cdn.platformdtc.com — static assets
- Storefronts and checkouts PlatformDTC hosts for merchants, including on merchants' own domains — for vulnerabilities in the PlatformDTC platform itself
Out of scope
- Content, apps and third-party scripts a merchant has added to their own store
- Services operated by third parties, including Stripe, PayPal, Authorize.net, Checkout.com, MyFatoorah, Cloudflare and Amazon Web Services — please report those to the provider
- Denial of service, load testing, or any testing that degrades service for others
- Social engineering or phishing of our staff, merchants or their customers, and physical attacks
- Reports generated by automated scanners without a demonstrated, exploitable impact
- Missing security headers, cookie flags, or email authentication (SPF, DKIM, DMARC) settings without a demonstrated attack
- Clickjacking on pages with no sensitive actions, self-XSS, and logout CSRF
- Rate limiting on endpoints that are not security-sensitive
- Issues that only affect outdated or unsupported browsers
Testing rules
- Use only accounts and stores you own or have explicit permission to test. You can create your own store to test with.
- Do not access, change or delete data that does not belong to you. If you encounter someone else's data, stop, do not keep a copy, and tell us in your report.
- Do not make payments with card details you are not authorised to use, and do not attempt to move funds or trigger payouts.
- Do not send email or SMS messages through the platform to people who have not agreed to receive them.
- Use a vulnerability only as far as needed to demonstrate it. Do not pivot to other systems or maintain access.
- Do not publicly disclose an issue before we have had a reasonable opportunity to fix it.
Safe harbor
If you make a good-faith effort to follow this policy during your security research, we will:
- Consider your research authorised, and not pursue or support legal action against you in relation to it
- Waive the restrictions in our Terms and Conditions and Acceptable Use Policy that would otherwise prohibit that research, to the extent needed for it
- Make it known that your activities were conducted in line with this policy if a third party brings legal action against you in relation to them
This safe harbor covers PlatformDTC's systems only. We cannot authorise testing of third-party services, including the payment and infrastructure providers listed above. If you are unsure whether your research is consistent with this policy, email us before you start.
Rewards
We do not offer monetary rewards or run a paid bug bounty.