Vulnerability disclosure policy
Last updated: September 30, 2026.
We want to hear about security problems in QuotWay. If you find one and report it to us in good faith under this policy, we will work with you to understand it and fix it - and we will not pursue legal action against you.
How to report
Email security@quotway.com. Include:
- the affected URL, API endpoint, or feature;
- the steps to reproduce it, and a proof of concept if you have one;
- the impact you believe it has;
- your name or handle (optional), and how to contact you.
Please don't include real personal data in your report. If you came across any, describe it rather than copying it.
Scope
In scope
api.quotway.com- the public REST API. Please use a Shopify development store and aqw_test_key wherever you can.app.quotway.com- the QuotWay admin app, its storefront app-proxy endpoints, and its API routes.portal.quotway.com- the hosted buyer portal.- Outbound webhooks - signing, secret handling, and our protections against server-side request forgery.
- QuotWay's storefront, customer-account, Shopify Flow, and Sidekick extensions, as they run on a store you own.
www.quotway.com- only for issues that affect users' security.
Out of scope
- Other merchants' stores, buyers, or data. Test only on a development store that you own.
- Shopify's own platform (admin, checkout, customer accounts). Report those through Shopify's bug bounty on HackerOne.
- Our vendors' platforms (Vercel, Neon, Sentry, toSend), unless the problem is caused by how QuotWay configures them.
- Denial-of-service, load or stress testing, rate-limit exhaustion, spam, social engineering, and physical attacks.
- Reports from automated scanners that don't show a real, working impact.
- Low-risk findings with no demonstrated impact. Examples:
- missing security headers, or cookie flags on cookies that aren't sensitive;
- clickjacking on pages with no sensitive actions;
- logout CSRF;
- version disclosure;
- email SPF/DKIM/DMARC settings;
- self-XSS.
Safe harbour
If you make a good-faith effort to follow this policy, we will consider your research authorized. We will not pursue or support legal action against you for it - including under anti-hacking laws, or for breach of our Terms of service or API terms of use.
To qualify, you must:
- Test only against accounts and stores you own, or have explicit permission to test.
- Stop as soon as you reach anyone else's data. Access no more than you need to show the issue, don't keep, change, delete, or share it, and tell us in your report.
- Not degrade the service for anyone. That means no denial-of-service, high-volume automated testing, or load testing.
- Not use the issue for any purpose other than confirming it, and not pivot to other systems.
- Give us reasonable time to fix the issue before you disclose it publicly.
- Comply with the law.
This safe harbour covers only QuotWay's own systems. We can't authorize testing of Shopify's or our vendors' systems.
What you can expect from us
| Step | Target |
|---|---|
| Acknowledge your report | Within 2 business days |
| Initial assessment | Within 5 business days |
| Progress updates | At least every 14 days until resolved |
| Fix - critical or high severity | Within 30 days of confirmation, sooner where we can |
| Fix - medium or low severity | Within 90 days of confirmation |
We don't currently run a paid bug bounty.
Found a leaked QuotWay key?
If you find a QuotWay API key (it starts with qw_live_ or qw_test_) or a webhook signing secret (it starts with whsec_) in a public place:
- Email
security@quotway.comwith where you found it. - Please don't use it, and don't include the full value in your email.
We will revoke it and tell the merchant who owns it.
Public disclosure
We prefer coordinated disclosure. Once a fix has shipped, or 90 days after your report (whichever comes first, unless we agree a different date), you're welcome to publish your findings. Please remove any personal data and any store identifiers first.