Security contact
How customers and researchers can report a suspected security or privacy issue without exposing more sensitive information.
Report safely
The monitored security address is pending verification and will be published here before checkout opens. Do not send a report to an address that has not been published on this page. Do not access another customer’s data or continue testing after confirming a vulnerability.
Never send
Do not email passwords, MFA codes or seeds, API keys, webhook secrets, database credentials, full payment-card details, government identity documents, raw customer exports, complete shipping addresses, or copied private data. Redact customer and provider identifiers whenever possible.
StarTaps controls
- Server-side authentication, authorization, tenant isolation, and administrator MFA.
- Signed and idempotent payment webhooks with fail-closed commerce controls.
- Restricted security headers, input validation, private storage, and bounded upload types.
- Privacy-preserving rate limits, constrained error logs, secret scanning, and protected source review.
- Mandatory production, redirect, analytics, and physical-device QA before shipment.
Response commitment
A formal response target, disclosure process, safe-harbor statement, and vulnerability-reward policy have not been approved. StarTaps will preserve a report, limit access, investigate proportionately, and communicate through the verified contact method once the operational procedure is approved.
A monitored support address will be published here before checkout opens. Do not send sensitive information to an unverified address.