Kogan Store logo Kogan Store

Kogan Store Trust Center

Responsible Disclosure

Kogan Store welcomes reports from security researchers and the security community who discover potential vulnerabilities in good faith. This policy explains what to report, how to report it, what is in scope, and what you can expect from us after submitting a report.

Effective Date: July 2020 Last Updated: July 2020 Author: Kogan Store Marketplace Operations

1. Our Commitment

Protecting our customers, sellers, partners, and marketplace infrastructure is one of our highest priorities. We appreciate the efforts of security researchers and ethical hackers who responsibly report potential vulnerabilities and help us maintain a safe, reliable platform.

Kogan Store is committed to reviewing valid security reports promptly, working collaboratively with researchers, protecting our users during the remediation process, fixing confirmed vulnerabilities as appropriate, and maintaining clear communication throughout the disclosure process.

2. Scope

This policy applies to Kogan Store owned and operated digital services, including:

  • Public marketplace and landing pages.
  • Buyer-facing store and product pages.
  • Seller dashboard and authentication flows.
  • Admin and super-admin dashboard interfaces.
  • APIs owned and operated by Kogan Store.
  • Authentication services under Kogan Store's control.

Third-party services integrated with Kogan Store are generally outside the scope of this policy and should be reported directly to the relevant provider.

3. Good Faith Research

Security research must always be conducted responsibly. Researchers are expected to:

  • Minimize the impact of any testing on platform availability and user experience.
  • Respect user privacy and avoid accessing data that does not belong to you.
  • Stop testing immediately if you encounter sensitive user data and report it without further access.
  • Report findings privately to Kogan Store before any public or third-party disclosure.
  • Not exploit a vulnerability beyond what is necessary to confirm it exists.

4. Safe Harbor

If you conduct security research in good faith and comply with this policy, Kogan Store will generally consider your research to be authorized. We do not intend to pursue legal action solely because you submitted a vulnerability report that follows this policy.

This safe harbor does not apply to activities that are unlawful, malicious, destructive, or outside the scope of responsible security research. Researchers who engage in prohibited activities described in this policy are not covered by this safe harbor.

5. How to Report a Vulnerability

Please submit your report through our official Contact page or Support Center. To help us investigate efficiently, include as much relevant information as possible:

  • A clear description of the issue and its potential security impact.
  • The affected URL, page, API endpoint, or feature.
  • Step-by-step instructions to reproduce the issue.
  • Screenshots or a proof of concept demonstrating the vulnerability, where safe to provide.
  • Browser, operating system, and device information.
  • Suggested remediation if you have one.

Do not submit customer personal data, payment data, KYC documents, or account credentials in your report. If you have encountered such data during research, describe what you found without reproducing or transmitting it.

6. Response Process

After receiving a report, Kogan Store aims to:

  • Acknowledge receipt of the report.
  • Review the submitted information and assess initial severity.
  • Reproduce and validate the reported issue.
  • Develop and deploy an appropriate fix where the vulnerability is confirmed.
  • Notify the researcher when the issue has been resolved, where appropriate.

Response times may vary depending on the complexity and severity of the report. We prioritise reports based on potential impact to users and platform integrity.

7. Coordinated Disclosure

To protect our users, we ask researchers not to publicly disclose technical details of a reported vulnerability until Kogan Store has had a reasonable opportunity to investigate and remediate the issue. Where appropriate, coordinated public disclosure may occur after remediation has been completed and verified.

8. Prohibited Activities

The following activities are not authorized under this policy and will not be covered by safe harbor protections:

  • Social engineering, phishing, or impersonation of Kogan Store staff.
  • Physical security testing of any facility or device.
  • Denial-of-service or distributed denial-of-service attacks.
  • Spam or unsolicited automated messaging campaigns.
  • Malware deployment or destructive testing.
  • Ransom or extortion attempts.
  • Accessing, modifying, or deleting data that belongs to other users.
  • Creating persistent unauthorized access to our systems.
  • Automated scanning that disrupts production services or degrades performance for real users.

9. Out of Scope

Unless specifically authorized, the following are generally outside the scope of this policy:

  • Third-party platforms, services, or integrations not directly controlled by Kogan Store.
  • Vulnerabilities requiring physical access to a device or facility.
  • Issues affecting unsupported or outdated browsers where no reasonable fix exists.
  • Reports that lack sufficient technical detail to reproduce or verify the issue.
  • Automated scanner output with no demonstrated security impact.
  • General best-practice recommendations that do not identify a specific, verifiable vulnerability.
  • Theoretical attacks with no practical exploitation path on the current platform.

10. Recognition

We appreciate responsible security research and the contribution it makes to a safer marketplace. At this time, Kogan Store does not operate a public bug bounty program or guarantee financial rewards unless explicitly announced. Where appropriate, we may recognize researchers who make significant contributions to improving platform security.

11. Confidentiality

Information shared during the vulnerability disclosure process should be treated as confidential by both parties until the issue has been resolved or coordinated disclosure has been agreed. We will treat the details of your report confidentially and will not share your identity without your permission.

12. Changes to This Policy

Kogan Store may update this Responsible Disclosure Policy to reflect changes in our services, infrastructure, security practices, or legal requirements. The latest version will always be published on this page.

13. Contact

If you believe you have discovered a security vulnerability affecting Kogan Store, please report it through our official Contact page or Support Center. Include sufficient technical information to help us investigate efficiently. We appreciate the efforts of the security community in helping us protect our marketplace.

Related Pages

Trust & Safety  ·  Privacy Policy  ·  Terms of Service  ·  Cookie Policy  ·  Payment Security  ·  Accessibility Statement  ·  Contact Us