Tapcart · Vulnerability Disclosure

Tapcart Vulnerability Disclosure

Vulnerability disclosure

Tapcart runs a published vulnerability disclosure program with a machine-readable RFC 9116 security.txt and stated triage SLAs. Note the discovery problem: neither the security.txt nor the policy page lives on tapcart.com. Both are served from security.tapcart.com — a Google Cloud Storage bucket named tapcart-vulnerability-program behind Cloudflare — and https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or scanner following RFC 9116 against the primary domain will not find this program.

Tapcart runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyMobileCommerceShopifyE-CommerceMobile AppsPush NotificationsAnalyticsWebhookDeveloper Tools
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@tapcart.co

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://security.tapcart.com/vulnerability-program.html
description: >-
  Tapcart runs a published vulnerability disclosure program with a
  machine-readable RFC 9116 security.txt and stated triage SLAs. Note the
  discovery problem: neither the security.txt nor the policy page lives on
  tapcart.com. Both are served from security.tapcart.com — a Google Cloud
  Storage bucket named tapcart-vulnerability-program behind Cloudflare — and
  https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or
  scanner following RFC 9116 against the primary domain will not find this
  program.
policy:
  - https://security.tapcart.com/vulnerability-program.html
  - https://security.tapcart.com/.well-known/security.txt
contact:
  - security@tapcart.co
bug_bounty:
  present: false
  note: >-
    No paid bounty and no HackerOne / Bugcrowd / Intigriti program was found.
    This is a coordinated disclosure program only.
security_txt:
  url: https://security.tapcart.com/.well-known/security.txt
  file: ../well-known/tapcart-security.txt
  fields:
    Contact: mailto:security@tapcart.co
    Expires: '2035-12-31T23:59:00Z'
    Policy: https://security.tapcart.com/.well-known/security.txt
    Preferred-Languages: en
  deviations:
    - >-
      The Policy field points back at security.txt itself rather than at the
      human-readable policy page (vulnerability-program.html), so an automated
      consumer following Policy gets the same file it already has.
    - >-
      Expires is set ~10 years out. RFC 9116 recommends less than a year so the
      file is demonstrably maintained.
    - No Encryption, Acknowledgments, Canonical, or Hiring fields.
sla:
  acknowledgement: 1 business day
  triage_and_severity: 3 business days
  remediation_critical: 7 days
  remediation_other: 30 days
scope:
  in_scope:
    - All publicly accessible Tapcart services
    - "*.tapcart.com subdomains"
    - Tapcart mobile app infrastructure
  out_of_scope:
    - Rate limiting and brute-force protections
    - Best-practice recommendations (e.g. use of certain headers)
    - Social engineering or physical attacks
pgp:
  required: false
  note: PGP is not required; Tapcart offers to arrange a secure channel on request.
evidence:
  - {source: 'https://security.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain}
  - {source: 'https://security.tapcart.com/vulnerability-program.html', kind: disclosure-policy, http_status: 200}
  - {source: 'https://www.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://api.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://dev.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
x-evidence:
  fetched: '2026-08-05'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tapcart-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.