01Report a Vulnerability
If you believe you have found a security vulnerability in Astrixy, tell us before you tell anyone else. Email security@astrixy.app. Machine-readable contact details are published at /.well-known/security.txt.
Include, where you can:
- A clear description of the issue and its security impact.
- Exact reproduction steps, request/response pairs, or a short proof-of-concept.
- The affected URL, endpoint, or component, and the time of testing.
- Your assessment of severity, and whether you intend to publish.
02Safe Harbour
We will not pursue legal action against, or ask law enforcement to investigate, researchers who act in good faith and comply with this policy. We consider such research authorised access under applicable computer-misuse laws, and we will make that position clear if a third party raises a claim. If you are unsure whether a test is in scope, ask us first — we would rather answer a question than receive an apology.
03Rules of Engagement
- Test only against accounts and stores you own, or a test account you create for the purpose.
- Stop as soon as you have confirmed a vulnerability. Do not enumerate, exfiltrate, or retain other users' data. If you access customer data accidentally, stop, tell us, and delete it.
- No denial-of-service, volumetric load testing, or resource exhaustion.
- No social engineering, phishing, or physical attacks against our staff, users, or vendors.
- No spam to merchants, and no automated scanning that degrades service for others.
- Do not publish details until we have shipped a fix or 90 days have passed, whichever comes first.
- Comply with all applicable law.
04In Scope
- www.astrixy.app and astrixy.app, including the merchant dashboard.
- Merchant storefronts hosted on Astrixy subdomains, where you own the store.
- Our public API endpoints and webhook receivers.
- Astrixy mobile applications.
- Authentication, session handling, tenant isolation, entitlement enforcement, and payment orchestration logic.
05Out of Scope
- Findings from automated scanners without a demonstrated exploit.
- Missing security headers, cookie flags, or TLS configuration with no proven impact.
- Rate limiting on non-authentication endpoints, and self-XSS.
- Clickjacking on pages with no state-changing action; CSRF on logout or other low-impact actions.
- Email spoofing of domains we do not send from, and SPF/DMARC issues on parked domains.
- Content injected by a merchant into their own storefront.
- Vulnerabilities in third-party services — report those to the vendor; tell us if we are exposed.
- Physical security, and attacks requiring a rooted device or a compromised end-user machine.
06Our Response Commitment
| Stage | Target |
|---|---|
| Acknowledgement | 1 business day |
| Triage and severity assignment | 3 business days |
| Fix — Critical | 72 hours |
| Fix — High | 7 days |
| Fix — Medium | 30 days |
| Fix — Low | 90 days |
We keep you updated at each stage and tell you when the fix is live so you can verify it.
07Recognition
Astrixy does not currently operate a paid bug bounty. We offer public acknowledgement in our security hall of fame with your preferred name and link, a written confirmation of the finding for your portfolio, and credit in the release notes. As revenue allows, we intend to introduce monetary rewards; researchers who reported valid issues beforehand will be considered when that programme launches.
08Encryption
For sensitive reports, request our PGP key from security@astrixy.app and we will supply the current fingerprint over a second channel before you send details.