Security and Responsible Disclosure Policy
Version: 2026-08-03
Effective date: 3 August 2026
MuthoCommerce protects a multi-tenant commerce platform containing merchant, shopper, order, message, and integration data. This Policy states the minimum security programme and a good-faith route for reporting vulnerabilities. It does not claim a certification or guarantee that incidents are impossible.
1. Security programme
MuthoCommerce will maintain a risk-based security programme that includes:
- server-enforced tenant separation and authorisation, with tests against cross- tenant data access;
- unique workforce accounts, least privilege, privileged multi-factor authentication, logged high-risk access, and quarterly access review;
- TLS in transit, provider-supported encryption at rest, managed secrets, credential rotation, and prohibition on logging secrets or full payment credentials;
- secure change review, dependency and vulnerability management, input and output controls, rate limiting, webhook verification, and idempotent side-effect handling;
- monitored operational and security events, named incident roles, evidence preservation, containment, notification assessment, and post-incident remediation;
- encrypted or provider-protected backups, documented recovery objectives, and at least annual restoration and deletion testing;
- vendor risk review, written security and incident terms, and termination handling; and
- workforce confidentiality, security training, and prompt offboarding.
Full payment-card numbers, mobile-financial-service PINs, passwords, and one-time codes are not intended to be stored by MuthoCommerce. When a connected payment provider hosts or tokenises a payment flow, that provider's security and compliance scope applies. MuthoCommerce will not claim PCI DSS, ISO 27001, SOC 2, or another certification until the exact Service scope has current independent evidence.
2. Reporting a vulnerability
Use the public Security Report channel on Contact MuthoCommerce. Encrypt the report with the published security key if it contains a sensitive proof. Include:
- the affected hostname, endpoint, feature, and account type;
- prerequisites and clear reproduction steps;
- the observed and expected result and realistic impact;
- the smallest safe proof, with secrets and personal data redacted;
- time and source IP of testing if useful for log review; and
- a secure contact and any disclosure deadline you are considering.
Do not send a vulnerability only through social media, a merchant, or a public issue tracker. If you believe there is active data exposure or imminent harm, mark the report urgent and stop testing.
MuthoCommerce will acknowledge a complete report within 2 business days, conduct initial severity triage within 5 business days, and provide a status update at least every 10 business days while a validated issue remains open. Remediation time depends on severity, exploitability, and safe deployment. MuthoCommerce will communicate a target after triage rather than promise an unsafe fixed deadline.
3. Good-faith research rules
Research is authorised only when all of these conditions are followed:
- test an account and store you own or for which the Owner gave written permission;
- use the minimum requests and data needed to demonstrate the issue;
- stop immediately if you encounter another person's data, credentials, message, order, or non-public system;
- do not download, retain, alter, destroy, publish, or share personal or confidential data; record only the minimum redacted evidence;
- do not create persistence, pivot to another system, escalate beyond what proves impact, or test a suspected payment against real funds;
- do not use social engineering, phishing, spam, physical intrusion, denial of service, high-volume automation, malware, ransomware, extortion, or supply-chain compromise;
- do not access employee, merchant, or third-party accounts without express written authority; and
- give MuthoCommerce a reasonable opportunity to investigate and remediate before public disclosure, and coordinate disclosure when doing so protects users.
Third-party systems, merchant-owned external services, connected payment/courier/ social providers, and physical facilities are out of scope unless their owner separately authorises testing. A custom domain that resolves to MuthoCommerce does not authorise testing that merchant's data or business.
4. Safe-harbour commitment
When a researcher acts in good faith, stays within this Policy, avoids privacy and service harm, and promptly reports the finding, MuthoCommerce will not initiate legal action solely for that research and will support clarification that the work was authorised under this Policy. This commitment does not bind another person or an authority, excuse unrelated unlawful conduct, waive Merchant rights, or authorise access beyond the limits above.
If accidental access occurs, stop, do not retain or share the data, identify the minimum affected location in the report, and follow MuthoCommerce's reasonable deletion instructions. Prompt, careful handling will be considered evidence of good faith.
5. Recognition and rewards
MuthoCommerce may credit a researcher only with permission. This Policy does not promise a bounty or payment. Any future reward programme must publish eligibility, severity, duplicate, exclusion, sanction, tax, and payment rules before the relevant report. Withholding a reward is not permission to disclose customer data.
6. Security incidents and customer notice
MuthoCommerce will assess suspected incidents using documented severity, data, tenant, legal, and safety criteria. Confirmed incidents affecting Merchant Personal Data are notified under the DPA without undue delay and, where reasonably practicable, within 48 hours after confirmation. MuthoCommerce will not delay containment to complete a perfect notice. Updates will distinguish confirmed facts from investigation and avoid exposing another customer's security information.