Legal
Security
How to tell us about a hole, and what we have already done about the obvious ones.
Last reviewed DATE
Reporting something
Email SECURITY EMAIL. Tell us what you found, where, and enough for us to reproduce it. You do not need a template and you do not need to prove impact before you write.
We will confirm we received it within three working days, tell you what we think within ten, and let you know when it is fixed. If we disagree that it is a problem we will say why rather than go quiet.
A machine readable security.txt goes up at /.well-known/security.txt as soon as the reporting address above exists.
Safe harbour
If you find something while acting in good faith under the rules below, we will not pursue you and we will not report you. We will treat your report as an attempt to help, because that is what it is.
- Test only against this site and only with accounts and data that are yours
- Stop as soon as you have confirmed a problem exists, and do not go further into it
- Do not access, change or keep anyone else's data. If you see some by accident, stop and tell us
- No denial of service, no load testing, no spam, no social engineering of us or our suppliers
- Give us a reasonable chance to fix it before you publish
We do not run a paid bounty. We will credit you here if you want, and we would rather say thank you in public than let a fix go out looking like it happened by itself.
Out of scope
- Anything on Google's systems, or on GCash, Maya, RCBC or GoTyme. Report those to whoever runs them; they have their own programmes
- Missing headers with no demonstrated impact, and scanner output pasted without a working case
- Reports that depend on an already compromised device, or on a browser extension the visitor installed
- Social engineering, physical access, and anything aimed at our staff rather than our software
What we already do
- No card fields anywhere on this siteYou pay in your own banking app against a QR code. There is nothing on this site that asks for a card number, a wallet PIN or a bank login, and there never will be
- Prices are calculated on the serverThe browser sends items and quantities, never an amount, so a tampered request cannot change what you are charged
- Nothing third party loads at allEvery script, font, stylesheet and image comes from our own domain. There is no tag manager and no analytics to compromise, and reading the site contacts nobody
- A content security policy that blocks the restScripts, frames, objects and form targets are restricted to this origin, and the site cannot be framed by anyone
- Browser storage is treated as hostileEverything read back out of local storage is validated and escaped before it can reach the page, because storage is writable by anything else running on the machine
- An uploaded receipt is not a confirmed paymentA screenshot can be forged, and software that reads one cannot tell. Every payment is checked by a person against our own account before an order is marked paid or anything is packed
What we have not done
We have not had a penetration test. The site has no login, so there are no accounts to take over, and no customer data is stored on this origin. The contact and mailing list forms are front end only until they are connected to something, and when they are they need server-side validation and rate limiting before they go live.
Saying this in public is deliberate. A security page that lists only strengths is marketing.
Bag (0)