Tapcart Vulnerability Disclosure Program

At Tapcart, the security of our platform and our customers’ data is a top priority. We appreciate responsible disclosures from the security community.

How to Report

If you believe you’ve found a security vulnerability in any of our services, please email us at [email protected].

Disclosure Policy

Scope

All publicly accessible Tapcart services are in scope, including *.tapcart.com subdomains and the Tapcart mobile app infrastructure.

Out of Scope

Tapcart does not consider the following to be vulnerabilities:

security.txt

We also support machine-readable disclosures. See our security.txt file for more details.

PGP Key

We currently do not require PGP for submissions. If you would prefer to encrypt your report, please reach out and we can arrange a secure channel.