Security and Vulnerability Disclosure
Effective and last reviewed
How to report a security flaw responsibly, and what we promise in return.
Report it here
security@themaplemarkets.ca. Include the affected URL or endpoint, reproduction steps, the impact you believe it has, and anything needed to verify it. We acknowledge within three business days and keep you updated until it is closed.
Safe harbour
If you act in good faith, stay within the rules below, and give us reasonable time to fix an issue before disclosing it, we will not pursue legal action against you and will treat your research as authorised.
Rules
Do not access, modify, exfiltrate or retain data belonging to anyone else. Do not run denial-of-service, volumetric or destructive tests, do not spam or social-engineer our staff, users or providers, and do not test third-party services we merely consume. Use your own test account. Stop as soon as you have proof of concept, and delete any data you incidentally obtained.
Scope and rewards
In scope: this website, its APIs and its authentication. Out of scope: missing best-practice headers with no demonstrated impact, rate-limit findings without a working exploit, self-XSS, reports produced solely by an automated scanner, and issues in third-party platforms. We do not operate a paid bounty programme at this time; we do credit reporters publicly with their consent.
Our commitments
We triage promptly, we do not silently ignore reports, and where a confirmed incident creates a real risk of significant harm we notify affected users and regulators on the timelines Canadian privacy law requires.
This page is maintained by The Maple Markets and is general information, not legal advice.
