Responsible disclosure
Security
This public catalog is separated from Bestimate’s internal seller operations. It does not contain SP-API credentials, Amazon order data, buyer information, or an internal sign-in surface.
Report a vulnerability
Please send a clear description, affected URL, reproduction steps, and impact to security@bestimate.ae. Do not access customer data, disrupt services, or use destructive testing.
Amazon information incidents
Bestimate’s internal incident response process treats suspected exposure of Amazon Information as urgent and includes notification to Amazon’s security contact within the required reporting window.
Scope
This policy covers shop.bestimate.ae. Reports concerning Bestimate’s other services can use the same security contact.