At Tapcart, the security of our platform and our customers’ data is a top priority. We appreciate responsible disclosures from the security community.
If you believe you’ve found a security vulnerability in any of our services, please email us at [email protected].
All publicly accessible Tapcart services are in scope, including *.tapcart.com subdomains and the Tapcart mobile app infrastructure.
Tapcart does not consider the following to be vulnerabilities:
We also support machine-readable disclosures. See our security.txt file for more details.
We currently do not require PGP for submissions. If you would prefer to encrypt your report, please reach out and we can arrange a secure channel.