Qruuk
Security

Reporting a security issue

If you think you’ve found a security problem in Qruuk, please tell us. We read every report and reply within three working days.

How to report

Email hello@qruuk.com with “Security” in the subject. Include what you found, the steps to reproduce it and the impact you expect. English or Estonian is fine.

What we ask

  • Only test with accounts you created yourself. Don’t access, change or keep anyone else’s data; if you come across some, stop and tell us.
  • No denial-of-service, spam, physical attacks or social engineering of our staff or merchants.
  • Give us reasonable time to fix the issue before telling anyone else.

What you can expect

  • A reply within three working days, and updates until it’s fixed.
  • Credit for the find, if you want it.
  • No legal action for research done in good faith within these rules.
  • We don’t run a paid bug bounty.

Known and by design

  • Open OAuth client registration at api.qruuk.com/oauth/register. AI apps register themselves this way under the MCP authorization specification. A registered app gets no access until a signed-in merchant approves it on the consent screen. Web return addresses are limited to known AI apps, and registration is rate-limited.
  • Public metadata: /.well-known/oauth-* documents and this file.
  • Reports without a security impact, such as missing headers on pages that hold no data, banner or version disclosure, or email SPF/DMARC policy settings.