Skip to main content
Stockaroo
FeaturesPlatformsPricingLoginStart Free Trial
FeaturesPlatformsPricingLoginStart Free Trial

Vulnerability Disclosure Policy

How to report a security problem in Stockaroo, what we commit to doing about it, and what is out of scope.

Last updated
14 September 2026
Effective
14 September 2026
Version
1.0
Contents
  1. How to report
  2. What we commit to
  3. Safe harbour
  4. In scope
  5. Out of scope
  6. No bounty

This document is a draft awaiting legal review. The safe-harbour wording in particular should be checked by a solicitor before anyone relies on it.

How to report

Email security@stockaroo.com. Please include enough detail to reproduce the issue: the URL or endpoint, the steps, and what you observed. A proof of concept helps; a video is rarely necessary.

If the report contains anything sensitive, say so and we will arrange an encrypted channel before you send it.

Please do not open a public issue, post on social media, or tell a third party until we have had a reasonable chance to fix it. See the timelines below for what "reasonable" means here.

What we commit to

Stockaroo is a small team. These are commitments we can actually keep:

Acknowledgement
Within 3 working days, from a person rather than an autoresponder.
Initial assessment
Within 10 working days we will tell you whether we have reproduced it, how we have rated it, and roughly when we expect to fix it.
Fix
Critical issues within 7 days, high within 30, in line with the standards our marketplace partners hold us to. Lower severities are scheduled and we will tell you when.
Disclosure
We will confirm when it is fixed. You are free to write it up after that, and we will not ask you to stay quiet indefinitely.
Credit
We will credit you by name if you want it, and will not if you do not.

Safe harbour

If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat your activity as authorised under the Computer Misuse Act 1990.

That protection depends on you staying within the rules below. In particular: test only against your own account, do not access, modify or retain anyone else's data, and stop as soon as you have demonstrated the problem.

If you are unsure whether something is in bounds, ask first. We would much rather answer a question than receive an apology.

In scope

  • The Stockaroo application and its API
  • The marketing site
  • The owner portal

We are most interested in anything that crosses a tenant boundary. Stockaroo gives every customer their own database, and a defect that lets one account reach another's data is the most serious class of bug we can have. Report that above anything else.

Also of high interest: authentication and session handling, anything touching the encrypted marketplace tokens, and anything that would let a request forge the identity headers our services trust.

Out of scope

These are either not vulnerabilities, or are things we have already decided about. Reporting them will get a polite decline rather than a fix:

  • Denial of service, volumetric or otherwise. Please do not test this at all — it affects real merchants' orders.
  • Social engineering, phishing, or physical access against us, our staff or our customers.
  • Automated scanner output submitted without a demonstrated impact.
  • Missing security headers or cookie flags with no exploitable consequence shown.
  • Weaknesses in third-party services — report those to the third party. Ours are listed on the sub-processors page.
  • Anything already disclosed on our security page. We publish the gaps we have not closed yet; finding one of those is not a discovery.

No bounty

We do not run a paid bug bounty and we are not going to pretend otherwise. What you get is a fast, honest response from someone who will actually fix it, and credit if you want it.

If that changes, this page will say so.

Stockaroo

One stash, every store. Multi-channel inventory and sales, finally in one place.

Product

  • Features
  • Pricing
  • Integrations

Company

  • Contact
  • Report a vulnerability

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Stockaroo. All rights reserved.