Trust, Safety & Resilience
Security & Vulnerability Reporting
We take the security of our platforms, client infrastructure, and proprietary applications seriously. Report security issues directly to our engineering response team.
Contact Our Security Response Team
If you have identified a potential security vulnerability, privilege escalation, or data exposure affecting Ullass or PosNova, report it directly:
Responsible Disclosure Guidelines
- A detailed summary of the vulnerability, including attack vector and severity assessment.
- Step-by-step reproduction instructions or a minimal Proof of Concept (PoC).
- Affected URLs, API endpoints, or platform components.
- Allow our engineering team reasonable time to remediate before public disclosure.
Our Security Commitment
Safe harbor for researchers
We will not take legal action against security researchers who conduct testing in good faith, avoid privacy violations, do not degrade production services, and report findings responsibly.
PosNova Security Inquiries
PosNova is a product by Ullass. Reports concerning POS multi-tenant isolation, storefront subdomains, payment webhooks, or API authentication fall within our high-priority security scope.
Reporting Policy Violations or Spam?
If your inquiry concerns spam, phishing, or acceptable use violations rather than a technical vulnerability, visit our Abuse Reporting Desk (abuse@ullass.com).
Security Architecture
Built-In Platform Security
How Ullass protects data, infrastructure, and user access across all software applications.
Responsible Disclosure
We welcome reports from security researchers and developers. We commit to acknowledging receipt promptly and working transparently toward remediation.
Data Isolation & Encryption
All systems engineered by Ullass enforce strict encryption in transit (TLS 1.3) and at rest, alongside role-based access control (RBAC).
Ecosystem Protection
Continuous dependency audits, automated CI/CD security scanning, and rate-limiting across our platform and applications, including PosNova.