• Pricing
  • Docs
Log inStart building

The platform that grows with your business.

From your first sale to global expansion. One unified platform for retail, wholesale, and everything in between.

Backed by

Zemuria Venture Studio

Commerce

  • Platform
  • Storefront Builder
  • Commerce
  • Digital Products
  • Payments
  • Shipping
  • Integrations

Growth

  • AI Sales Agent
  • Optimize
  • Marketing & Email
  • Content & Blog
  • Reviews
  • Customer Accounts
  • Analytics
  • SEO Features

Company

  • About
  • Pricing
  • Customers
  • Careers
  • Partners
  • Experts
  • Startups
  • Changelog

Developers

  • Developer overview
  • API documentation
  • API reference
  • Quickstart
  • Authentication
  • MCP server
  • CLI
  • Open source

Support

  • Contact us
  • Help centre
  • System status
  • Trust centre
  • Security policy

Compare Platforms

  • Mercemur vs Shopify
  • Mercemur vs WooCommerce

Legal

  • Legal overview
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • Refund Policy
  • Sub-processors
  • Accessibility

Contact

Zemuria Inc.

1007 N Orange St., 4th Floor, #1189
Wilmington, Delaware 19801

support@mercemur.com

Copyright © 2026 by Mercemur, a Zemuria Inc. brand.

  • Terms of service
  • Privacy
  • Refund

Security

Coordinated Vulnerability Disclosure

How to report security vulnerabilities to Mercemur. Scope, safe harbor, response SLAs, and the timeline we commit to for coordinated disclosure.

  1. Home
  2. /
  3. Security
  4. /
  5. Vulnerability Disclosure Policy
•Last updated: May 30, 2026

On this page

  1. Purpose
  2. Scope
  3. Safe harbor
  4. Reporting channels
  5. Response SLA
  6. Coordinated disclosure timeline
  7. Hall of Fame
  8. Rate limit coordination
  9. What not to do
  10. Contact and PGP

Purpose

Mercemur welcomes coordinated vulnerability reports from external security researchers, customers, merchants, and the public. This policy describes what is in scope, how to report, the safe harbor we provide for good-faith research, and the timeline we will work to with you.

Scope

In scope

  • mercemur.com, www.mercemur.com, api.mercemur.com, app.mercemur.com, stores.mercemur.com, cdn.mercemur.com, status.mercemur.com, docs.mercemur.com
  • Merchant custom domains where Mercemur is responsible for the application layer
  • Public APIs documented in our OpenAPI spec
  • Mercemur-owned mobile clients (when released)
  • Mercemur-owned GitHub repositories that are publicly accessible

Out of scope

  • Social engineering of Mercemur employees, contractors, or merchants
  • Physical attacks against Mercemur facilities, employees, or vendors
  • Denial-of-service testing
  • Third-party services (Stripe, Razorpay, Dodo, Wasabi, Cloudflare, Resend, GitHub, Google), report to those vendors directly
  • Testing against live merchant data or live merchant accounts without their explicit consent
  • Spam-related reports (DMARC, SPF, DKIM misconfigurations), use abuse channels
  • Issues already reported and tracked by Mercemur
  • Issues requiring physical access or an already-compromised endpoint device

Safe harbor

Mercemur will not pursue civil or criminal action against researchers who in good faith comply with this policy. Specifically, please:

  • Make every effort to avoid privacy violations, data destruction, service interruption, and degradation.
  • Only interact with accounts you own or have explicit permission to access.
  • Do not exfiltrate data. Proof of concept only.
  • Stop testing and notify us immediately if you encounter sensitive data.
  • Do not disclose publicly before the coordinated timeline expires.
  • Comply with all applicable laws.

If you are uncertain whether a particular activity is in scope, write to support@mercemur.com before proceeding.

Reporting channels

  • Primary, PGP-encrypted email: support@mercemur.com. PGP key at /.well-known/pgp-key.txt.
  • Contact form: mercemur.com/contact, if email is not feasible. Mark the message as a security report so it is routed rather than queued with general enquiries.
  • Postal mail: Zemuria Inc., Bengaluru registered office, as a last resort.

Please include: a vulnerability description, affected systems, reproduction steps, observed impact, a CVSS-style severity estimate, your contact info (or "anonymous"), and any preferred coordinated disclosure timeline.

Response SLA

SeverityAcknowledgmentTriagePatch targetDisclosure window
Critical24 hours3 business days7 days30 days minimum, 90 days maximum
High24 hours5 business days30 days60 to 90 days
Medium3 business days10 business days90 days90 days
Low5 business days15 business days180 days90 days

If we cannot meet a patch target, the Security Lead will negotiate an extension with the researcher. The disclosure clock pauses while patches are tested with researcher cooperation.

Coordinated disclosure timeline

Default 90 days from initial report. Negotiable based on severity, complexity, and whether active exploitation is observed. With your consent, you receive credit on our Hall of Fame once patches are deployed and disclosure is appropriate.

Hall of Fame

We credit researchers for valid coordinated disclosures, with their consent, and will name the venue for those credits when the first one is published. A bug bounty program is targeted for 2027 Q1. Until then: public credit and Mercemur swag for valid reports.

Rate limit coordination

If you plan sustained testing against /licenses/validate, /hooks/*, or /store/customers/me/downloads/*, please announce your source IP range to support@mercemur.com first. Otherwise our Cloudflare WAF and backend rate limiters will treat your probes as an attack.

What not to do

  • Do not exfiltrate any data, including synthetic data.
  • Do not disrupt service for other merchants or end customers.
  • Do not pivot to other merchants' data.
  • Do not access employee or customer accounts beyond your own test account.
  • Do not publicly disclose before the agreed timeline.
  • Do not extort, threaten, or demand payment in exchange for disclosure.
  • Do not test against production merchant data without explicit consent.

Contact and PGP

Primary contact: support@mercemur.com. PGP key at /.well-known/pgp-key.txt and on keys.openpgp.org.

PGP fingerprint: 65A4 2B91 7E03 D5C8 0F1B 94E2 88AC 7F3D 1234 5678

Our machine-readable contact card lives at /.well-known/security.txt per RFC 9116.