Security Policy

Last updated: Aug 26, 2026

At Peddle, we take the security of our systems and the protection of our customers' data seriously. We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our services, and we are committed to working with you to verify, resolve, and, where appropriate, reward valid findings. This page describes what we consider in scope, how to report an issue, and how rewards are determined.

The quickest way to reach our security team is by email at cybersecurity@peddle.com. A machine-readable summary of this policy is published at /.well-known/security.txt.

Scope

At this time we are primarily interested in Critical (P1) and High (P2) severity issues affecting Peddle's production services and the data they hold. Lower-severity reports are still welcome and will be reviewed, but may not always be eligible for a reward.

When investigating a potential vulnerability, please observe the following boundaries:

  • Do not perform testing that degrades, disrupts, or denies service to our production services or its users. This includes denial-of-service (DoS) testing, load or stress testing, and automated attacks against live accounts.
  • Do not access, modify, or delete data that does not belong to you. Use test accounts you control wherever possible.
  • Report findings; do not exploit them. Please limit your activity to what is strictly necessary to demonstrate the issue, and stop as soon as you have confirmed it.
  • Do not use social engineering, phishing, or physical attacks against Peddle employees, contractors, or facilities.

P3 and P4 reports may be eligible for a discretionary reward when they demonstrate meaningful impact.

Rewards

We assess each valid report based on its impact and assign a severity tier. The ranges below are guidelines. We confirm the reward amount in writing before payment is issued.

  • P1 - Severe impact (e.g. account takeover or remote code execution): USD $1,000-$3,000+
  • P2 - Major impact (e.g. account compromise, unauthorized access, or privilege escalation): USD $300-$900
  • P3 - Medium impact (e.g. limited unauthorized disclosure of account data or a local denial-of-service condition): USD $200-$300
  • P4 - Minor impact (e.g. a low-severity issue or a previously unknown, low-severity issue): USD $100 or Peddle-branded merchandise

Reward amounts are confirmed with the reporter before any payment is made, and payment is issued once a reward agreement is signed. Only the first reporter of a previously unknown, valid issue is eligible for a reward. We reserve the right to determine severity and eligibility at our discretion.

How to report

Please email your report to cybersecurity@peddle.com with enough detail for us to understand and confirm the issue. A good report includes:

  • What you found and where (for example, the affected URL, endpoint, or page).
  • The impact (what an attacker could do with the issue).
  • Clear, step-by-step instructions to reproduce it.
  • Supporting evidence, such as a short write-up, a screenshot, or an example request.

We will acknowledge your report within 48 hours and give you an estimated timeline for resolution. Please give us a reasonable amount of time to investigate and remediate before disclosing an issue publicly.

Handling of data

Once you have submitted your report, please securely delete any Peddle data you accessed or copied during testing from your systems. Do not retain, share, or publish Peddle data obtained through your research.

Safe harbor

We consider security research conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy. If legal action is initiated by a third party against you for activity that was conducted in accordance with this policy, we will make this authorization known. If you are ever unsure whether specific testing is consistent with this policy, contact us at cybersecurity@peddle.com before proceeding.