Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→Now onboarding tailor stores in TerzyApp — from the UK◆Apply to join→
TerzyApp LogoTerzyApp
About UsBlogFAQFor TailorsFabric BrandsContact
Get App via TestFlight
TerzyApp LogoTerzyApp

The global marketplace for custom-made clothing — AI-powered body scan measurement from your phone, luxury fabrics from world-class mills, virtual try-on, and master tailors who craft every piece to your exact body.

Get App via TestFlightEarly access via TestFlight for now — App Store coming soon.

Product

  • How TerzyApp works
  • FAQ

Company

  • About Us
  • Blog
  • For Tailors
  • Fabric Brands
  • Contact

Legal

  • Brand Assets
  • Security
  • Privacy
  • Investors

Backed by

NVIDIA Inception Program memberAWS Startups member

New partnerships coming soon.

© 2026 TerzyApp. All rights reserved.

Security

Help us keep TerzyApp safe.

We're a new startup building a global tailoring marketplace — and we know we can't do security alone. If you find something real, we want to hear from you.

01

An honest note on rewards.

We're early. We don't have a formal bug bounty budget yet, and we can't legally promise payouts.

Here's what we can promise:

  • We read every report. Carefully.
  • We move fast on anything real.
  • We credit you publicly — on this page and across our social channels.
  • As we grow and funding allows, we want to start rewarding the people who help us stay safe. That's a promise we can keep.
02

We won't punish you for helping us.

If you act in good faith, stay within scope, give us reasonable time to respond, and don't access user data beyond what's needed to demonstrate the issue — we will not pursue legal action against you.

03

What we want to hear about.

  • Authentication bypass, broken access control, IDOR
  • Remote code execution, SQL injection, server-side request forgery
  • Stored or reflected XSS with real impact
  • Sensitive data exposure (PII, payment data, internal credentials)
  • Payment manipulation or commission tampering
  • Account takeover paths

Where to look:

terzyapp.com, dashboard.terzyapp.com, api.terzyapp.com, TerzyApp for iOS, TerzyApp for Android.

04

What we already know about — please don't send these.

  • Missing security headers without a working exploit
  • Denial-of-service attacks or volumetric testing
  • Social engineering of staff or customers
  • Physical attacks against our offices or hardware
  • Vulnerabilities in third-party services we depend on (report those to them)
  • Self-XSS, clickjacking on pages without sensitive actions
  • Outdated software versions without a proven exploit path
05

Reach us through the contact form.

Use our /contact page and select “Security Report” as the topic. Include reproduction steps, affected URL or endpoint, and your preferred way of being credited (real name, handle, or anonymous).

Submit a security report
06

Our wall — coming soon.

When researchers help us, their names land here and on our social channels. Be the first.

Your name here

Your name here

Your name here

07

Thank you for caring.

We're building TerzyApp for the long run. Every responsible disclosure makes us better.