BarterNow Security Policy
Responsible Disclosure
If you believe you have found a security vulnerability in BarterNow, report it to [email protected]. Include the affected URL or endpoint, reproduction steps, impact, and any relevant request or response details with secrets redacted.
Safe Testing
Please avoid destructive testing, social engineering, spam, denial-of-service testing, credential attacks, data exfiltration, and attempts to access accounts or data that do not belong to you. Use a test account and stop immediately if you encounter personal, financial, or confidential business data.
Response Process
We aim to acknowledge valid reports within 48 hours, triage severity, and coordinate remediation based on impact. We may ask for additional technical details if the report cannot be reproduced from the initial submission.
Production Operations
BarterNow uses HTTPS, security headers, scoped authentication, CSRF protections, rate limiting, structured security logging, and provider-side payment verification. Security issues involving payments, authentication, authorization, or private user data receive priority handling.