Legal · CommerceOS by Bizzar Marketing

Security & disclosure

If you have found a security flaw in CommerceOS, tell us — this page says how, what we care about most, and what happens next. CommerceOS is operated by Bizzar Marketing; every store on the platform runs our software, so a flaw in it is ours to fix, not the shop's.

Last updated August 27, 2026

How to report

Email [email protected]with “security” in the subject. Include what you found, the steps to reproduce it, and what an attacker could do with it. Screenshots or a short recording help. The same contact is published in machine-readable form at /.well-known/security.txt (RFC 9116).

You will get a human reply. We aim to acknowledge within two working days and to tell you what we found — including when we decide something is not a vulnerability, and why.

Please report these first

These are the failures that would hurt real merchants and real shoppers, in order:

  • Cross-tenant access— any way one store reads or writes another store’s data. This is the one we care about above everything else.
  • Checkout or payment tampering — changing a price, a total, an order state, or a refund from outside the API.
  • Theme or block injection — getting script or style you control to run on a storefront or in the merchant dashboard.
  • Account takeover — anything that gets you into a merchant account, a buyer account, or the platform console without the credentials.

Please do not

  • Run automated scanners against merchant storefronts. They are live businesses taking real orders, and a scanner is indistinguishable from an attack while it runs. Ask us and we will give you a test store to work against.
  • Place real orders, issue refunds, or otherwise move money to demonstrate a finding.
  • Access, modify, or download data belonging to anyone else. Stop as soon as you have confirmed the issue — one record is proof; a dump is a breach.
  • Degrade the service: no denial-of-service testing, no load generation.
  • Social-engineer our staff, our merchants, or their customers.

What you can expect from us

  • An acknowledgement, and updates while we work on it.
  • Credit in the release notes if you want it, and none if you would rather stay anonymous.
  • No legal action for good-faith research that follows this page. If you are unsure whether something is in scope, ask first — we would rather answer a question than receive a report you were nervous about sending.

We do not run a paid bug bounty. We say so plainly rather than leaving it ambiguous: your time is worth something and you should know before you spend it.

Out of scope

  • A merchant’s own content and configuration. Products, prices, policies, and anything a store owner typed are theirs — report those to the store.
  • Findings that are only reachable with a merchant’s own credentials acting on their own store. That is the merchant using their dashboard.
  • Reports produced entirely by a scanner with no demonstrated impact, missing hardening headers with no exploit path, and version-disclosure banners.
  • Issues in third-party services we integrate with (payment gateways, the CDN, the mail provider) — report those to them; tell us too if it affects CommerceOS merchants.

How we handle your report

We triage on severity and blast radius, fix cross-tenant and money-path issues ahead of everything else on the roadmap, and ship the fix before publishing anything about it. Where a flaw affected merchant data we tell the affected merchants what happened, what was reached, and when.

Contacting us

Bizzar Marketing
Murgasole, Asansol – 713303, West Bengal, India
[email protected]