PlatformDTC
EnterprisePricingAbout UsAnswersBlogDocs

Vulnerability Disclosure Policy

Last updated: September 11, 2026

Keeping merchant and customer data safe matters to us, and we welcome reports from security researchers. This policy explains what you may test, how to report what you find, what you can expect from us, and the safe harbor we offer to anyone who follows it in good faith.


How to report

Email security@platformdtc.com. Please include:

  • The affected host, URL or feature
  • The type of vulnerability
  • Step-by-step instructions to reproduce it, including any requests, payloads, screenshots or video
  • The impact: what an attacker could do with it
  • The accounts or store identifiers you used while testing
  • How we can reach you with follow-up questions

One report per vulnerability helps us track and fix each issue. Please include no more personal data about anyone else than you need to demonstrate the issue.


What to expect from us

  • We acknowledge every report within 48 hours.
  • We will tell you whether we were able to reproduce the issue, and let you know when it has been fixed.
  • Please give us a reasonable opportunity to investigate and fix the issue before you disclose it publicly, and coordinate the timing of any disclosure with us.

Scope

In scope

Systems PlatformDTC operates:

  • platformdtc.com and www.platformdtc.com — our website and the merchant dashboard
  • api.platformdtc.com — the PlatformDTC API, including the Agent Gateway
  • checkout.platformdtc.com, and the /checkout, /cart and /pay paths on platformdtc.com — hosted checkout
  • accounts.platformdtc.com
  • docs.platformdtc.com — developer documentation
  • status.platformdtc.com — the status page
  • mail.platformdtc.com — webmail
  • cdn.platformdtc.com — static assets
  • Storefronts and checkouts PlatformDTC hosts for merchants, including on merchants' own domains — for vulnerabilities in the PlatformDTC platform itself

Out of scope

  • Content, apps and third-party scripts a merchant has added to their own store
  • Services operated by third parties, including Stripe, PayPal, Authorize.net, Checkout.com, MyFatoorah, Cloudflare and Amazon Web Services — please report those to the provider
  • Denial of service, load testing, or any testing that degrades service for others
  • Social engineering or phishing of our staff, merchants or their customers, and physical attacks
  • Reports generated by automated scanners without a demonstrated, exploitable impact
  • Missing security headers, cookie flags, or email authentication (SPF, DKIM, DMARC) settings without a demonstrated attack
  • Clickjacking on pages with no sensitive actions, self-XSS, and logout CSRF
  • Rate limiting on endpoints that are not security-sensitive
  • Issues that only affect outdated or unsupported browsers

Testing rules

  • Use only accounts and stores you own or have explicit permission to test. You can create your own store to test with.
  • Do not access, change or delete data that does not belong to you. If you encounter someone else's data, stop, do not keep a copy, and tell us in your report.
  • Do not make payments with card details you are not authorised to use, and do not attempt to move funds or trigger payouts.
  • Do not send email or SMS messages through the platform to people who have not agreed to receive them.
  • Use a vulnerability only as far as needed to demonstrate it. Do not pivot to other systems or maintain access.
  • Do not publicly disclose an issue before we have had a reasonable opportunity to fix it.

Safe harbor

If you make a good-faith effort to follow this policy during your security research, we will:

  • Consider your research authorised, and not pursue or support legal action against you in relation to it
  • Waive the restrictions in our Terms and Conditions and Acceptable Use Policy that would otherwise prohibit that research, to the extent needed for it
  • Make it known that your activities were conducted in line with this policy if a third party brings legal action against you in relation to them

This safe harbor covers PlatformDTC's systems only. We cannot authorise testing of third-party services, including the payment and infrastructure providers listed above. If you are unsure whether your research is consistent with this policy, email us before you start.


Rewards

We do not offer monetary rewards or run a paid bug bounty.


Related

  • Security
  • security.txt
  • Contact

PlatformDTC

One platform to run your brand. Agents included.

Resources

  • Answers
  • Glossary
  • Agent Readiness Checker
  • DTC AI Crawler Index
  • Blog
  • Pricing
  • Explore all pages

Company

  • About Us
  • Enterprise
  • Talk to Sales
  • Contact
  • Developer Docs
  • System Status
  • Community

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • All policies

© Copyright 2026 PlatformDTC. All Rights Reserved.