Security
Reporting a security problem
If you have found a security weakness in Ottom, write to [email protected] with the word Security in the subject. A person reads every report. This page says what to send, what we do with it, and what we ask of you while we fix it.
What to send
- The page, route or feature where the problem is.
- The steps that show it, in order, so we can see it for ourselves.
- What someone could do with it, as far as you know.
- How you would like to be named when we thank you, or that you would rather not be.
Please do not send us anybody else’s personal data, even as proof. A screenshot of your own account or test data is enough.
What we promise
- A reply from a person within 5 working days, saying whether we can reproduce it.
- Updates as we work on it, and word from us when it is fixed.
- No legal action against anyone who finds and reports a problem in good faith and within the rules below.
We do not run a paid bug bounty.
What we ask of you
- Use your own account and your own data. Stop as soon as you reach anyone else’s.
- Do not change or delete data, degrade the service, or send large volumes of automated traffic.
- No phishing, social engineering or physical attempts against us or our suppliers.
- Give us 90 days to fix it before you publish anything, or tell us why that is too long and we will talk about it.
Out of scope
- Findings from an automated scanner with no demonstrated impact, such as a header you would like us to add.
- Problems in Stripe, Shopify, Google or other services we use. Report those to them.
- Our agents visiting your store. That is not a security problem, and there is a separate address for it: [email protected]. How it works is on our agent disclosure page.
For tools
The same contact is published in machine-readable form at /.well-known/security.txt, following RFC 9116.