# CommerceOS — security contact (RFC 9116) # # This file is served by every CommerceOS surface, including storefronts running on # merchants' own domains. A store's owner does not operate this software and cannot patch # it; the platform operator can. Report anything you find here, not to the shop. Contact: mailto:support@commerceos.online Contact: https://www.trycommerceos.com/security Expires: 2027-08-27T00:00:00.000Z Preferred-Languages: en Canonical: https://www.trycommerceos.com/.well-known/security.txt Policy: https://www.trycommerceos.com/security # A STORE on CommerceOS that is phishing, defrauding shoppers, spreading malware or pretending # to be someone else is not a vulnerability report — report the site here instead, no account # needed: https://www.trycommerceos.com/report-abuse # What we care about most, in order: cross-tenant access (one store reading or writing # another's data), checkout and payment tampering, theme or block injection, and account # takeover. Please do not run automated scanners against merchant storefronts — they are real # businesses taking real orders. Ask us for a test store instead. # # We do not run a paid bounty. We will acknowledge your report, keep you updated, and credit # you if you want to be credited.