Back Market · Vulnerability Disclosure
Back Market Vulnerability Disclosure
Vulnerability disclosure
Back Market runs a coordinated vulnerability disclosure program announced through an RFC 9116 security.txt served identically from every regional storefront and PGP-signed by security@backmarket.com. Reports go to that mailbox and Back Market asks that they be encrypted and attached to the mail rather than pasted in the body. There is no public bug bounty program (no HackerOne / Bugcrowd / Intigriti / YesWeHack listing was found) and Back Market states it is under no obligation to reward a disclosure.
Back Market runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyE-CommerceMarketplaceRetailRefurbished ElectronicsCircular EconomyOrdersListingsProduct CatalogLogisticsCustomer Support
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security@backmarket.com