name: Lightspeed Commerce Vulnerability Disclosure generated: '2026-08-27' method: searched source: https://www.lightspeedhq.com/security/ policy_url: https://www.lightspeedhq.com/security/ http_status: 200 probed: '2026-08-27' security_txt: present: false probed: - url: https://www.lightspeedhq.com/.well-known/security.txt status: 404 - url: https://x-series-api.lightspeedhq.com/.well-known/security.txt status: 404 - url: https://developers.lightspeedhq.com/.well-known/security.txt status: 404 - url: https://api.shoplightspeed.com/.well-known/security.txt status: 404 bug_bounty: claimed: true statement: >- "We operate a public bug bounty program to encourage ethical research and responsible disclosure." — https://www.lightspeedhq.com/security/ program_url: null note: >- Lightspeed states it runs a PUBLIC bug bounty program but publishes no link to it, no scope, no safe-harbour text and no reporting address anywhere on the security page. hackerone.com/lightspeed and bugcrowd.com/lightspeed both return HTTP 200 JavaScript shells that name no organisation, so neither could be attributed to Lightspeed Commerce and neither is recorded here. A researcher who finds a vulnerability today has no published intake path. security_testing: - Routine vulnerability scanning across codebases and deployments - Annual internal and external penetration testing by third-party firms - Formal security policies reviewed at least annually incident_notification: >- Affected merchants are notified with remediation steps and ongoing updates when unauthorized access to merchant data is identified. gaps: - No security.txt on any host. - No bug bounty program URL, scope or safe-harbour statement. - No dedicated security contact address published.