Catulie

Security

Last updated 18 August 2026

How this shop is built to keep an order — and the person who placed it — safe.

Payments

Card data never touches this site. Checkout hands off to a PCI DSS Level 1 payment processor, which returns only a payment reference. The shop stores that reference, not a card number.

In transit and at rest

Access control

Application

Reporting a vulnerability

Email security@catulie.com, or see /.well-known/security.txt. We aim to acknowledge within two business days. Please give us a reasonable window to fix an issue before disclosing it, and do not access other people's data while testing. Researchers who report in good faith are credited on the acknowledgements page if they want to be.