Responsible disclosure
Report security issues without putting merchants at risk.
If you believe you found a vulnerability in Metrico, report it privately with enough detail for us to reproduce and investigate it.
Last updated: September 30, 2026
How to report
Email ahmedabdelrahma@gmail.com with “Security report” in the subject.
Include
- The affected URL, route, feature, or provider integration.
- Clear reproduction steps and the security impact you observed.
- Any request or response details with secrets and personal data redacted.
- A safe way to contact you for clarification.
Please avoid
- Accessing, altering, or deleting data that does not belong to you.
- Disrupting production service, rate limits, or connected provider APIs.
- Social engineering, credential theft, spam, denial of service, or physical attacks.
- Publishing an unpatched issue before there has been a reasonable opportunity to investigate and remediate it.
Good-faith research
Reports made in good faith should minimize access to real merchant data and stop once the security impact is demonstrated. This page is not permission to test third-party systems such as Shopify, Meta, TikTok, Google, Vercel, or other providers outside the scope of Metrico's own service.
Response expectations
Metrico will prioritize reports according to demonstrated impact and exploitability. Acknowledgement and remediation timing can vary with severity, reproducibility, dependencies, and provider involvement, so this page does not promise a fixed resolution window.