Last updated: Aug 26, 2026
At Peddle, we take the security of our systems and the protection of our customers' data seriously. We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our services, and we are committed to working with you to verify, resolve, and, where appropriate, reward valid findings. This page describes what we consider in scope, how to report an issue, and how rewards are determined.
The quickest way to reach our security team is by email at cybersecurity@peddle.com. A machine-readable summary of this policy is published at /.well-known/security.txt.
At this time we are primarily interested in Critical (P1) and High (P2) severity issues affecting Peddle's production services and the data they hold. Lower-severity reports are still welcome and will be reviewed, but may not always be eligible for a reward.
When investigating a potential vulnerability, please observe the following boundaries:
P3 and P4 reports may be eligible for a discretionary reward when they demonstrate meaningful impact.
We assess each valid report based on its impact and assign a severity tier. The ranges below are guidelines. We confirm the reward amount in writing before payment is issued.
Reward amounts are confirmed with the reporter before any payment is made, and payment is issued once a reward agreement is signed. Only the first reporter of a previously unknown, valid issue is eligible for a reward. We reserve the right to determine severity and eligibility at our discretion.
Please email your report to cybersecurity@peddle.com with enough detail for us to understand and confirm the issue. A good report includes:
We will acknowledge your report within 48 hours and give you an estimated timeline for resolution. Please give us a reasonable amount of time to investigate and remediate before disclosing an issue publicly.
Once you have submitted your report, please securely delete any Peddle data you accessed or copied during testing from your systems. Do not retain, share, or publish Peddle data obtained through your research.
We consider security research conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy. If legal action is initiated by a third party against you for activity that was conducted in accordance with this policy, we will make this authorization known. If you are ever unsure whether specific testing is consistent with this policy, contact us at cybersecurity@peddle.com before proceeding.