Security
Reporting a security issue
If you think you’ve found a security problem in Qruuk, please tell us. We read every report and reply within three working days.
How to report
Email hello@qruuk.com with “Security” in the subject. Include what you found, the steps to reproduce it and the impact you expect. English or Estonian is fine.
What we ask
- Only test with accounts you created yourself. Don’t access, change or keep anyone else’s data; if you come across some, stop and tell us.
- No denial-of-service, spam, physical attacks or social engineering of our staff or merchants.
- Give us reasonable time to fix the issue before telling anyone else.
What you can expect
- A reply within three working days, and updates until it’s fixed.
- Credit for the find, if you want it.
- No legal action for research done in good faith within these rules.
- We don’t run a paid bug bounty.
Known and by design
- Open OAuth client registration at
api.qruuk.com/oauth/register. AI apps register themselves this way under the MCP authorization specification. A registered app gets no access until a signed-in merchant approves it on the consent screen. Web return addresses are limited to known AI apps, and registration is rate-limited. - Public metadata:
/.well-known/oauth-*documents and this file. - Reports without a security impact, such as missing headers on pages that hold no data, banner or version disclosure, or email SPF/DMARC policy settings.