Vulnerability Disclosure Policy
How to report a security problem in Stockaroo, what we commit to doing about it, and what is out of scope.
- Last updated
- 14 September 2026
- Effective
- 14 September 2026
- Version
- 1.0
This document is a draft awaiting legal review. The safe-harbour wording in particular should be checked by a solicitor before anyone relies on it.
How to report
Email security@stockaroo.com. Please include enough detail to reproduce the issue: the URL or endpoint, the steps, and what you observed. A proof of concept helps; a video is rarely necessary.
If the report contains anything sensitive, say so and we will arrange an encrypted channel before you send it.
Please do not open a public issue, post on social media, or tell a third party until we have had a reasonable chance to fix it. See the timelines below for what "reasonable" means here.
What we commit to
Stockaroo is a small team. These are commitments we can actually keep:
- Acknowledgement
- Within 3 working days, from a person rather than an autoresponder.
- Initial assessment
- Within 10 working days we will tell you whether we have reproduced it, how we have rated it, and roughly when we expect to fix it.
- Fix
- Critical issues within 7 days, high within 30, in line with the standards our marketplace partners hold us to. Lower severities are scheduled and we will tell you when.
- Disclosure
- We will confirm when it is fixed. You are free to write it up after that, and we will not ask you to stay quiet indefinitely.
- Credit
- We will credit you by name if you want it, and will not if you do not.
Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat your activity as authorised under the Computer Misuse Act 1990.
That protection depends on you staying within the rules below. In particular: test only against your own account, do not access, modify or retain anyone else's data, and stop as soon as you have demonstrated the problem.
If you are unsure whether something is in bounds, ask first. We would much rather answer a question than receive an apology.
In scope
- The Stockaroo application and its API
- The marketing site
- The owner portal
We are most interested in anything that crosses a tenant boundary. Stockaroo gives every customer their own database, and a defect that lets one account reach another's data is the most serious class of bug we can have. Report that above anything else.
Also of high interest: authentication and session handling, anything touching the encrypted marketplace tokens, and anything that would let a request forge the identity headers our services trust.
Out of scope
These are either not vulnerabilities, or are things we have already decided about. Reporting them will get a polite decline rather than a fix:
- Denial of service, volumetric or otherwise. Please do not test this at all — it affects real merchants' orders.
- Social engineering, phishing, or physical access against us, our staff or our customers.
- Automated scanner output submitted without a demonstrated impact.
- Missing security headers or cookie flags with no exploitable consequence shown.
- Weaknesses in third-party services — report those to the third party. Ours are listed on the sub-processors page.
- Anything already disclosed on our security page. We publish the gaps we have not closed yet; finding one of those is not a discovery.
No bounty
We do not run a paid bug bounty and we are not going to pretend otherwise. What you get is a fast, honest response from someone who will actually fix it, and credit if you want it.
If that changes, this page will say so.