Lightspeed Commerce · Vulnerability Disclosure

Lightspeed Vulnerability Disclosure

Vulnerability disclosure

Lightspeed Commerce runs a coordinated vulnerability disclosure program on Hackerone.

CommercePoint-of-SaleRetailRestaurantInventoryLoyaltyPaymentsE-CommerceOmnichannel
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
name: Lightspeed Commerce Vulnerability Disclosure
generated: '2026-08-27'
method: searched
source: https://www.lightspeedhq.com/security/
policy_url: https://www.lightspeedhq.com/security/
http_status: 200
probed: '2026-08-27'
security_txt:
  present: false
  probed:
  - url: https://www.lightspeedhq.com/.well-known/security.txt
    status: 404
  - url: https://x-series-api.lightspeedhq.com/.well-known/security.txt
    status: 404
  - url: https://developers.lightspeedhq.com/.well-known/security.txt
    status: 404
  - url: https://api.shoplightspeed.com/.well-known/security.txt
    status: 404
bug_bounty:
  claimed: true
  statement: >-
    "We operate a public bug bounty program to encourage ethical research and responsible disclosure."
    — https://www.lightspeedhq.com/security/
  program_url: null
  note: >-
    Lightspeed states it runs a PUBLIC bug bounty program but publishes no link to it, no scope, no
    safe-harbour text and no reporting address anywhere on the security page. hackerone.com/lightspeed
    and bugcrowd.com/lightspeed both return HTTP 200 JavaScript shells that name no organisation, so
    neither could be attributed to Lightspeed Commerce and neither is recorded here. A researcher who
    finds a vulnerability today has no published intake path.
security_testing:
- Routine vulnerability scanning across codebases and deployments
- Annual internal and external penetration testing by third-party firms
- Formal security policies reviewed at least annually
incident_notification: >-
  Affected merchants are notified with remediation steps and ongoing updates when unauthorized access
  to merchant data is identified.
gaps:
- No security.txt on any host.
- No bug bounty program URL, scope or safe-harbour statement.
- No dedicated security contact address published.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lightspeed-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.