Skip to content

Security

Vulnerability Disclosure Policy

Effective: September 30, 2026

CartCycle LLC takes the security of our platform and our users' data seriously. We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue affecting CartCycle, please follow this policy when reporting it.

How to Report

Send a written report to trycartcycle@gmail.com. If your report contains sensitive technical details, you may encrypt it using our PGP key (see below).

Include in your report:

  • A description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Affected URL(s) or component(s)
  • Any supporting materials (screenshots, proof-of-concept code)

What We Ask

  • Give us reasonable time to investigate and remediate before public disclosure.
  • Do not access, modify, or delete data belonging to other users.
  • Do not perform denial-of-service testing against our infrastructure.
  • Do not use automated scanners in a way that generates excessive traffic.
  • Act in good faith throughout the process.

What You Can Expect

  • An acknowledgment of your report within 5 business days.
  • Regular updates on our progress toward a fix.
  • Credit for responsible disclosure, if you would like it, when the issue is resolved.

We do not currently offer a paid bug bounty program. We do offer our sincere thanks and public acknowledgment to researchers who help keep CartCycle secure.

Scope

This policy applies to security issues in:

  • mycartcycle.com and its subdomains
  • CartCycle backend services and APIs
  • CartCycle mobile and web applications

Out of scope: third-party services used by CartCycle (report those directly to the vendor), social engineering, physical security, and attacks requiring physical access to a user's device.

Contact

Security reports: trycartcycle@gmail.com

Machine-readable disclosure information: /.well-known/security.txt