Tapcart · Vulnerability Disclosure

Tapcart Vulnerability Disclosure

Vulnerability disclosure

Tapcart runs a published vulnerability disclosure program with a machine-readable RFC 9116 security.txt and stated triage SLAs. Note the discovery problem: neither the security.txt nor the policy page lives on tapcart.com. Both are served from security.tapcart.com — a Google Cloud Storage bucket named tapcart-vulnerability-program behind Cloudflare — and https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or scanner following RFC 9116 against the primary domain will not find this program.

Tapcart runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyMobileCommerceShopifyEcommerceMobile AppsPush NotificationsAnalyticsWebhooksDeveloper Tools
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@tapcart.co

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://security.tapcart.com/vulnerability-program.html
description: >-
  Tapcart runs a published vulnerability disclosure program with a
  machine-readable RFC 9116 security.txt and stated triage SLAs. Note the
  discovery problem: neither the security.txt nor the policy page lives on
  tapcart.com. Both are served from security.tapcart.com — a Google Cloud
  Storage bucket named tapcart-vulnerability-program behind Cloudflare — and
  https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or
  scanner following RFC 9116 against the primary domain will not find this
  program.
policy:
  - https://security.tapcart.com/vulnerability-program.html
  - https://security.tapcart.com/.well-known/security.txt
contact:
  - security@tapcart.co
bug_bounty:
  present: false
  note: >-
    No paid bounty and no HackerOne / Bugcrowd / Intigriti program was found.
    This is a coordinated disclosure program only.
security_txt:
  url: https://security.tapcart.com/.well-known/security.txt
  file: ../well-known/tapcart-security.txt
  fields:
    Contact: mailto:security@tapcart.co
    Expires: '2035-12-31T23:59:00Z'
    Policy: https://security.tapcart.com/.well-known/security.txt
    Preferred-Languages: en
  deviations:
    - >-
      The Policy field points back at security.txt itself rather than at the
      human-readable policy page (vulnerability-program.html), so an automated
      consumer following Policy gets the same file it already has.
    - >-
      Expires is set ~10 years out. RFC 9116 recommends less than a year so the
      file is demonstrably maintained.
    - No Encryption, Acknowledgments, Canonical, or Hiring fields.
sla:
  acknowledgement: 1 business day
  triage_and_severity: 3 business days
  remediation_critical: 7 days
  remediation_other: 30 days
scope:
  in_scope:
    - All publicly accessible Tapcart services
    - "*.tapcart.com subdomains"
    - Tapcart mobile app infrastructure
  out_of_scope:
    - Rate limiting and brute-force protections
    - Best-practice recommendations (e.g. use of certain headers)
    - Social engineering or physical attacks
pgp:
  required: false
  note: PGP is not required; Tapcart offers to arrange a secure channel on request.
evidence:
  - {source: 'https://security.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain}
  - {source: 'https://security.tapcart.com/vulnerability-program.html', kind: disclosure-policy, http_status: 200}
  - {source: 'https://www.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://api.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://dev.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404}
x-evidence:
  fetched: '2026-08-05'