Responsible Disclosure Policy

Last updated: 24 September 2026

Customers trust us with their documents, addresses and payments. If you believe you have found a security vulnerability in Printster, please tell us privately so we can fix it before anyone is harmed. We will not take legal action against researchers who follow this policy in good faith.

How to report

Please include:

  • The affected URL, app screen or API endpoint
  • A description of the issue and its likely impact
  • Step-by-step instructions to reproduce it, with any proof-of-concept code or screenshots
  • How you would like to be credited, if at all

In scope

  • The Printster website, ordering app and customer account pages
  • The Printster API used by our website and apps
  • The Printster WhatsApp ordering bot

Out of scope

  • Third-party services we use, such as our payment gateway, couriers and email providers. Please report those to the vendor directly.
  • Denial-of-service attacks, load testing, spam or social engineering of our staff or customers
  • Physical attacks on our offices or print facilities
  • Reports from automated scanners without a demonstrated impact
  • Missing best-practice headers or cookie flags with no demonstrated exploit, clickjacking on pages with no sensitive action, and self-XSS

Rules for testing

  • Only test against accounts and orders you own, or that you create for testing.
  • Never access, change, download or delete another customer’s files, orders or personal data. If you accidentally see such data, stop, do not keep a copy, and tell us in your report.
  • Do not place real orders you do not intend to pay for, and do not attempt to obtain free goods, discounts or wallet credit.
  • Do not degrade the service for other users.
  • Give us a reasonable time to fix the issue before sharing details with anyone else.

What you can expect from us

StepOur target
Acknowledge your reportWithin 3 working days
Confirm whether the issue is valid and share our assessmentWithin 10 working days
Fix critical and high-severity issuesAs a priority, and we will keep you updated

We do not currently run a paid bug bounty. With your permission, we are happy to thank you publicly once the issue is fixed.

Safe harbour

If you make a good-faith effort to follow this policy, we will consider your research authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. This does not authorise testing that breaks the law or violates the privacy of others.