Tapcart · Vulnerability Disclosure
Tapcart Vulnerability Disclosure
Vulnerability disclosure
Tapcart runs a published vulnerability disclosure program with a machine-readable RFC 9116 security.txt and stated triage SLAs. Note the discovery problem: neither the security.txt nor the policy page lives on tapcart.com. Both are served from security.tapcart.com — a Google Cloud Storage bucket named tapcart-vulnerability-program behind Cloudflare — and https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or scanner following RFC 9116 against the primary domain will not find this program.
Tapcart runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyMobileCommerceShopifyEcommerceMobile AppsPush NotificationsAnalyticsWebhooksDeveloper Tools
Program: Hackerone
security.txt present
Disclosure Policy
Policy
Policy
Security Contact
Contact
security@tapcart.co