# security.txt — RFC 9116 # # How to report a security vulnerability in the Dukan-X platform. # Served at https://dukan-x.com/.well-known/security.txt # # NOTE FOR OPERATORS: `Expires` MUST be refreshed before the date below, and the # Contact address must be a mailbox that is actually monitored. A stale or # unmonitored security.txt is worse than none — it promises a channel that is not # being read. See docs/security-headers.md. Contact: mailto:security@dukan-x.com Contact: https://dukan-x.com/contact Expires: 2027-09-03T00:00:00.000Z Preferred-Languages: ar, en Canonical: https://dukan-x.com/.well-known/security.txt Policy: https://dukan-x.com/terms # In scope # dukan-x.com and its subdomains, including merchant storefronts on *.dukan-x.com # and merchant custom domains served by this platform. # # Out of scope # Denial-of-service and volumetric testing, social engineering of staff or # merchants, automated scanner output with no demonstrated impact, and any # testing against a live merchant's real customer data. # # What we ask # Report privately and give us a reasonable window to fix before disclosure. # Use your own test store. Do not access, modify or exfiltrate data belonging to # another merchant or shopper — a proof of concept showing that you COULD is # enough, and is what we want. # # What to expect # Acknowledgement within 3 business days, and an assessment with a remediation # timeline within 10 business days.