Tapcart Vulnerability Disclosure
Tapcart runs a published vulnerability disclosure program with a machine-readable RFC 9116 security.txt and stated triage SLAs. Note the discovery problem: neither the security.txt nor the policy page lives on tapcart.com. Both are served from security.tapcart.com — a Google Cloud Storage bucket named tapcart-vulnerability-program behind Cloudflare — and https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or scanner following RFC 9116 against the primary domain will not find this program.
Tapcart runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.