Skip to main content
27Notice27Back to product

Security and responsible reporting

The plugin stays local; payment and download access stay separated.

Notice27 is designed to minimize data and dependencies. This page describes the current implementation, not a certification or penetration-test claim.

Draft security and responsible-disclosure policy for professional review.

Last updated: 27 July 2026

Plugin boundary

Version 1.2 contains no outbound HTTP request, telemetry, advertising, licence server, remote asset, customer-data read, or custom authentication. It stores one settings option in the merchant's WordPress database.

Settings are sanitized; output is escaped; the reset action requires the WooCommerce management capability and a valid WordPress nonce.

Website, payment, and delivery

Stripe Checkout handles card data. The Notice27 server uses the configured secret only to create/retrieve Checkout Sessions and checks complete, paid, matching product metadata before serving the protected ZIP.

Never email a Stripe key, WordPress password, card number, customer export, database, or production backup.

Report a vulnerability

Email contact@kastovia.com with “Notice27 security” in the subject, affected version/URL, impact, and safe reproduction steps. Do not access other customers' data, disrupt service, or publish an unremediated exploit.

Kastovia has not yet approved a response-time or bounty promise. Receipt and remediation will be handled according to severity and available evidence.

Notice27 is operated by Kastovia Holdings LLC, identification number 402371679, Lochini 3, apt 5, 0100 Tbilisi, Georgia.

DocsCompatibilitySecurityPrivacyTermsRefundsSupport