Report Security Issues
Pegas takes the security of our store and customer data seriously. If you are a security researcher or customer and believe you've found a vulnerability affecting pegasinc.com, we want to hear from you.
How to report
Email security@pegasinc.com with: (1) a description of the issue and its potential impact, (2) clear steps to reproduce it, and (3) any relevant screenshots, request/response data, or proof-of-concept code. Please use a descriptive subject line such as "Security Report – [brief summary]".
What we ask of you
Please act in good faith: do not access, modify, or delete data that isn't yours; do not run automated scanning that could disrupt store availability for other shoppers; do not publicly disclose an issue until we've had a reasonable opportunity to address it; and do not attempt to test for vulnerabilities on third-party services we use (such as our payment processor) — report those directly to the relevant provider.
What to expect from us
We aim to acknowledge reports within 5 business days and will keep you updated as we investigate and remediate confirmed issues. We do not currently operate a paid bug bounty program, but we're genuinely grateful for responsible disclosure and will credit researchers who ask to be credited once a fix is live.
Out of scope
Social engineering of staff or customers, physical security issues, and denial-of-service testing are out of scope for this program.
Contact Us
Address: 716 Whitney St, San Leandro, CA 94577
Email: security@pegasinc.com
Phone Number: +1 786-887-2721