Security
How we protect the platform, and how to tell us when we have not.
Draft — not yet reviewed by a lawyer. Written to common practice for a hosted commerce platform and accurate about how Stashed actually works, but it should be reviewed before it is relied on.
How the platform is protected
- All traffic is served over TLS. Storefronts on custom domains get certificates automatically.
- Card details are handled by our payment provider and never reach our servers.
- Passwords are handled by our authentication provider and are never stored by us in a recoverable form.
- Access to production systems is limited to those who need it and is authenticated individually.
- Merchant-supplied code is confined to that merchant’s own domain, so it cannot reach another shop or the platform session.
- Content Security Policy, rate limiting and request validation are applied at the edge.
Reporting a vulnerability
Email security@stashed.one with enough detail to reproduce the issue. We aim to acknowledge within two business days and to keep you updated while we work on it.
We will not take legal action against you for research conducted in good faith under the guidelines below, and we are happy to credit you publicly once the issue is fixed, if you would like that.
Research guidelines
- Test only against your own account and your own shop.
- Do not access, modify or delete anyone else’s data — if you can demonstrate access, stop and tell us.
- Do not run denial-of-service tests, spam, or social engineering against our staff, merchants or their customers.
- Give us reasonable time to fix an issue before disclosing it publicly.
Out of scope
- Findings from automated scanners without a demonstrated impact.
- Missing security headers with no exploitable consequence.
- Issues in a merchant’s own custom code or third-party theme.
- Social engineering, physical attacks, and anything requiring a compromised device.
Breach notification
If a data breach occurs that is likely to result in serious harm, we notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we notify affected merchants without undue delay.
Akashi Labs — Melbourne, Victoria, Australia — legal@stashed.one