generated: '2026-08-05' method: searched probe: true source: https://security.tapcart.com/vulnerability-program.html description: >- Tapcart runs a published vulnerability disclosure program with a machine-readable RFC 9116 security.txt and stated triage SLAs. Note the discovery problem: neither the security.txt nor the policy page lives on tapcart.com. Both are served from security.tapcart.com — a Google Cloud Storage bucket named tapcart-vulnerability-program behind Cloudflare — and https://www.tapcart.com/.well-known/security.txt returns 404. A researcher or scanner following RFC 9116 against the primary domain will not find this program. policy: - https://security.tapcart.com/vulnerability-program.html - https://security.tapcart.com/.well-known/security.txt contact: - security@tapcart.co bug_bounty: present: false note: >- No paid bounty and no HackerOne / Bugcrowd / Intigriti program was found. This is a coordinated disclosure program only. security_txt: url: https://security.tapcart.com/.well-known/security.txt file: ../well-known/tapcart-security.txt fields: Contact: mailto:security@tapcart.co Expires: '2035-12-31T23:59:00Z' Policy: https://security.tapcart.com/.well-known/security.txt Preferred-Languages: en deviations: - >- The Policy field points back at security.txt itself rather than at the human-readable policy page (vulnerability-program.html), so an automated consumer following Policy gets the same file it already has. - >- Expires is set ~10 years out. RFC 9116 recommends less than a year so the file is demonstrably maintained. - No Encryption, Acknowledgments, Canonical, or Hiring fields. sla: acknowledgement: 1 business day triage_and_severity: 3 business days remediation_critical: 7 days remediation_other: 30 days scope: in_scope: - All publicly accessible Tapcart services - "*.tapcart.com subdomains" - Tapcart mobile app infrastructure out_of_scope: - Rate limiting and brute-force protections - Best-practice recommendations (e.g. use of certain headers) - Social engineering or physical attacks pgp: required: false note: PGP is not required; Tapcart offers to arrange a secure channel on request. evidence: - {source: 'https://security.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain} - {source: 'https://security.tapcart.com/vulnerability-program.html', kind: disclosure-policy, http_status: 200} - {source: 'https://www.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404} - {source: 'https://api.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404} - {source: 'https://dev.tapcart.com/.well-known/security.txt', kind: security.txt, http_status: 404} x-evidence: fetched: '2026-08-05'