How to report
Email [email protected]with “security” in the subject. Include what you found, the steps to reproduce it, and what an attacker could do with it. Screenshots or a short recording help. The same contact is published in machine-readable form at /.well-known/security.txt (RFC 9116).
You will get a human reply. We aim to acknowledge within two working days and to tell you what we found — including when we decide something is not a vulnerability, and why.
Please report these first
These are the failures that would hurt real merchants and real shoppers, in order:
- Cross-tenant access— any way one store reads or writes another store’s data. This is the one we care about above everything else.
- Checkout or payment tampering — changing a price, a total, an order state, or a refund from outside the API.
- Theme or block injection — getting script or style you control to run on a storefront or in the merchant dashboard.
- Account takeover — anything that gets you into a merchant account, a buyer account, or the platform console without the credentials.
Please do not
- Run automated scanners against merchant storefronts. They are live businesses taking real orders, and a scanner is indistinguishable from an attack while it runs. Ask us and we will give you a test store to work against.
- Place real orders, issue refunds, or otherwise move money to demonstrate a finding.
- Access, modify, or download data belonging to anyone else. Stop as soon as you have confirmed the issue — one record is proof; a dump is a breach.
- Degrade the service: no denial-of-service testing, no load generation.
- Social-engineer our staff, our merchants, or their customers.
What you can expect from us
- An acknowledgement, and updates while we work on it.
- Credit in the release notes if you want it, and none if you would rather stay anonymous.
- No legal action for good-faith research that follows this page. If you are unsure whether something is in scope, ask first — we would rather answer a question than receive a report you were nervous about sending.
We do not run a paid bug bounty. We say so plainly rather than leaving it ambiguous: your time is worth something and you should know before you spend it.
Out of scope
- A merchant’s own content and configuration. Products, prices, policies, and anything a store owner typed are theirs — report those to the store.
- Findings that are only reachable with a merchant’s own credentials acting on their own store. That is the merchant using their dashboard.
- Reports produced entirely by a scanner with no demonstrated impact, missing hardening headers with no exploit path, and version-disclosure banners.
- Issues in third-party services we integrate with (payment gateways, the CDN, the mail provider) — report those to them; tell us too if it affects CommerceOS merchants.
How we handle your report
We triage on severity and blast radius, fix cross-tenant and money-path issues ahead of everything else on the roadmap, and ship the fix before publishing anything about it. Where a flaw affected merchant data we tell the affected merchants what happened, what was reached, and when.
Contacting us
Bizzar MarketingMurgasole, Asansol – 713303, West Bengal, India
[email protected]