SaaS is open · Start your store for free
All documentation

security · security

ACTIVE

Authorized security testing policy

Authorized testing

Authorized testing

Written scope and authorization are required before security testing. By default exclude DoS, destructive actions, real merchant/customer data, social engineering, third-party providers, production, and unapproved cloud systems. Use local fixtures or an explicitly assigned test environment.

ACTIVE · 2026-08-21 · docs/security/testing-policy.md

Help us improve SaaS

We'd like to use privacy-respecting analytics to understand how the platform is used and make it better. No personal data is collected without your consent, and you can change your choice anytime. Read our privacy notice