Security
Vulnerability Disclosure Policy
Effective: September 30, 2026
CartCycle LLC takes the security of our platform and our users' data seriously. We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue affecting CartCycle, please follow this policy when reporting it.
How to Report
Send a written report to trycartcycle@gmail.com. If your report contains sensitive technical details, you may encrypt it using our PGP key (see below).
Include in your report:
- A description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Affected URL(s) or component(s)
- Any supporting materials (screenshots, proof-of-concept code)
What We Ask
- Give us reasonable time to investigate and remediate before public disclosure.
- Do not access, modify, or delete data belonging to other users.
- Do not perform denial-of-service testing against our infrastructure.
- Do not use automated scanners in a way that generates excessive traffic.
- Act in good faith throughout the process.
What You Can Expect
- An acknowledgment of your report within 5 business days.
- Regular updates on our progress toward a fix.
- Credit for responsible disclosure, if you would like it, when the issue is resolved.
We do not currently offer a paid bug bounty program. We do offer our sincere thanks and public acknowledgment to researchers who help keep CartCycle secure.
Scope
This policy applies to security issues in:
- mycartcycle.com and its subdomains
- CartCycle backend services and APIs
- CartCycle mobile and web applications
Out of scope: third-party services used by CartCycle (report those directly to the vendor), social engineering, physical security, and attacks requiring physical access to a user's device.
Contact
Security reports: trycartcycle@gmail.com
Machine-readable disclosure information: /.well-known/security.txt