快工助手跨境电商知识与商机助手

[Policy Update] Migration of Penetration Test Report Submission to Open Platform

Shopee 官方资料 · Shopee Open Platform 变更通知(Announcements) · 适合开发者

stable本次发布有变化全部展示

来自 Shopee 官方资料快照 ·

打开官方原文 ↗
  1. 当前资料结构化阅读页
  2. 固定快照已留存,可追溯
  3. 官方原文可核对
查看技术与溯源信息
平台 / profile
Shopee / profile.shopee.announcements
语言
en
发布版本
cn-20260909-2
标签
zhuge/sourceplatform/shopeeaudience/developercategory/announcementtopic/apitopic/changelogtopic/developertopic/developer-policy

资料正文

§1 [Policy Update] Migration of Penetration Test Report Submission to Open Platform

This announcement is provided in Thai, English, and Chinese

[อัปเดตนโยบาย] การย้ายช่องทางการส่งรายงานการทดสอบการเจาะระบบ (Penetration Test) ไปยัง Open Platform Console

เรียน ผู้พัฒนา Third-party Partner Platform (ISV),

เราขอแจ้งให้ท่านทราบเกี่ยวกับความเปลี่ยนแปลงของขั้นตอนการส่งรายงานการทดสอบการเจาะระบบ (Penetration Test Report) ภายใต้นโยบายการคุ้มครองข้อมูล (DPP) ของ Shopee Open Platform

เพื่อเพิ่มความชัดเจนในการติดตามสถานะ เพิ่มประสิทธิภาพในการตรวจสอบ และพัฒนาประสบการณ์ที่ดีของนักพัฒนา Shopee จะทำการย้ายช่องทางการส่งรายงานจากเดิมผ่านทางอีเมล ไปยัง Open Platform Console

ผลกระทบต่อนักพัฒนา

● มีผลทันที: รายงานการทดสอบการเจาะระบบทั้งหมดจะต้องส่งผ่าน Shopee Open Platform Console เท่านั้น

● ยกเลิกการส่งผ่านทางอีเมล: ระบบจะไม่รับพิจารณารายงานที่ส่งผ่านอีเมลอีกต่อไป

● นักพัฒนาที่เคยส่งรายงานผ่านอีเมลหรือ Open Platform Console มาก่อน จำเป็นต้อง ส่งรายงานการทดสอบการเจาะระบบอีกครั้งผ่าน Open Platform Console

การอัปเดตครั้งนี้จะช่วยให้:

● การตรวจสอบสถานะการส่งรายงานและผลการพิจารณาได้ในที่เดียว

● มีระบบบันทึกข้อมูลส่วนกลางเพื่อตรวจสอบอายุการใช้งานของรายงานและการต่ออายุ

● รองรับการอัปโหลดเอกสารประกอบได้หลายฉบับผ่าน Open Platform Console (เช่น รายงานการทดสอบการเจาะระบบ, ใบรับรอง ISO/IEC 27001 และรายงาน SOC 2 Type II) แทนข้อจำกัดเดิมที่สามารถอัปโหลดได้เพียงเอกสารฉบับเดียว

🔔 สำคัญ: การอัปเดตนี้มีผลเฉพาะ "วิธีการส่ง" เท่านั้น ข้อกำหนดของนโยบาย ระยะเวลาที่รายงานมีผลบังคับใช้ และเกณฑ์การพิจารณาทั้งหมดยังคงเดิมไม่เปลี่ยนแปลง

คำแนะนำขั้นตอนการส่งใหม่

ขั้นตอนการส่งรายงานการทดสอบการเจาะระบบ:

  1. เข้าสู่ระบบ Open Platform Console ด้วย บัญชีนักพัฒนา (developer account)

หมายเหตุ: บัญชีสมาชิก (member account) ไม่มีสิทธิ์อัปโหลดรายงาน

  1. ไปที่ Personal Center → Account Information (ISV ในจีนแผ่นดินใหญ่: Link , ISV ในภูมิภาคอื่น ๆ: Link)

  2. ในส่วน Security Reports & Certifications Information ให้คลิก Add

  3. ภายใต้หัวข้อ Security Report & Certification Type ให้เลือก “Penetration Test Report”

  4. อัปโหลดรายงานล่าสุดของคุณ

  5. คลิก Submit

ระยะเวลา/วิธีการตรวจสอบสถานะเอกสาร

● โดยปกติจะทราบผลการตรวจสอบภายใน 10 วันทำการ

● ผู้พัฒนาสถานะการตรวจสอบเอกสาร (อนุมัติ / ปฏิเสธ) ในเมนู Account Information

คำถามที่พบบ่อย (FAQ)

1.หากฉันส่งรายงานผ่านอีเมลไปแล้วต้องทำอย่างไร?

A: ทีม Shopee OpenAPI ขอขอบคุณนักพัฒนาที่ส่งรายงานผ่านอีเมล อย่างไรก็ตาม เพื่อสอดคล้องกับกระบวนการใหม่ นักพัฒนาจำเป็นต้อง ส่งรายงานการทดสอบการเจาะระบบอีกครั้งผ่าน Open Platform Console

  1. หากฉันเคยอัปโหลดรายงานลงใน Open Platform Console จำเป็นต้องส่งอีกครั้งหรือไม่?

  2. มีการเปลี่ยนแปลงนโยบายการส่งรายงานการทดสอบการเจาะระบบหรือไม่ และต้องส่งเอกสารเมื่อใด?

A: ไม่มีการเปลี่ยนแปลง นโยบายเดิมยังคงบังคับให้นักพัฒนา ISV ที่ให้บริการแก่ผู้ขายใ ประเทศไทย และต้องการเข้าถึงข้อมูลส่วนบุคคลของผู้ซื้อ (PII) ส่งรายงานการทดสอบการเจาะระบบ (Penetration Test Report) ● รายงานที่อนุมัติแล้วมีอายุ 2 ปี นับตั้งแต่วันที่ได้รับอนุญาติ ● ISV ที่ไม่ส่งรายงานตามกำหนด อาจถูก จำกัดการเข้าถึงข้อมูล PII ซึ่งจะส่งผลกระทบต่อฟีเจอร์และกระบวนการทำงานที่ต้องพึ่งพาข้อมูล PII ● กำหนดส่งภายใน: 1 มีนาคม 2569

  1. ทำไมฉันจึงไม่เห็นปุ่ม ‘เพิ่ม’ ในข้อมูลบัญชี?

A: กรุณาตรวจสอบว่าคุณเข้าสู่ระบบ Open Platform Console ด้วยบัญชีนักพัฒนา (developer account) บัญชีสมาชิก (member account) สามารถดูข้อมูลได้เท่านั้นไม่สามารถแก้ไขหรืออัปโหลดเอกสารได้

----------------------------------------------------------------------------------------------------------------------

Dear Third-party Partner Platform (ISV) Developers,

We would like to inform you of an update to the Penetration Test Report submission process under the Shopee Open Platform Data Protection Policy (DPP).

To improve submission visibility, review efficiency, and overall developer experience, Shopee will be migrating the submission channel or Penetration Test Reports from email to the Open Platform Console.

Impact on Developers

Effective immediately, all Penetration Test Reports must be submitted via the Shopee Open Platform Console. New submissions via email will no longer be accepted.

Developers who have previously submitted their reports via email or the Open Platform Console are required to re-submit their Penetration Test Reports through the Open Platform Console.

This update provides:

● Clear submission status and review results in one place

● Centralized record-keeping for report validity and renewals

● Ability to upload multiple supporting documents in Open Platform console (e.g. Penetration Test Report, ISO/IEC 27001 Certificate, SOC 2 Type II Report), replacing the previous single-document limitation.

🔔 Important: This update applies only to the submission method.

All existing policy requirements, validity periods, and review criteria remain unchanged.

Updated Submission Instructions

To submit your Penetration Test Report:

● Step 1: Log in to your Open Platform console using your developer account

Note: Member accounts do not have permission to upload reports.

● Step 2: Navigate to Personal Center → Account Information (Chinese Mainland ISVs: Link, Other Region ISVs: Link)

● Step 3: Under Security Reports & Certifications Information, click "Add"

● Step 4: Under Security Report & Certification Type, Choose “Penetration Test Report”

● Step 5: Upload your latest penetration test report

● Step 6: Click “Save”

Review Timeline

● The submission status (Approved / Rejected) will be displayed in the Account Information section

● Review results are typically available within 10 working days

FAQ

  1. What if I already emailed my penetration test report?

A: The Shopee OpenAPI Team sincerely thanks developers who promptly submitted their Penetration Test Reports via email following the earlier announcement.

To align with the updated submission process, developers are required to re-submit their Penetration Test Report through the Open Platform Console. Reports submitted via email will no longer be reviewed under the new process.

For reports that were previously approved via email, as long as the report is still within its validity period, it will be approved again upon re-submission through the Open Platform Console.

  1. What if I already uploaded my penetration test report onto the Open Platform Console?

A: As part of the system upgrade, some previously uploaded security documents may not be fully integrated into the updated platform. To ensure your information is complete and up to date, re-submission is necessary.

  1. Have there been any changes to the Penetration Test Report submission policy, and when must the documents be submitted?

A: There are no changes from what was previously announced. Submission of penetration test report is mandatory for ISV developers that provide services to sellers in Thailand and require access to, or wish to maintain access to, buyers’ personal identifiable information (PII).

● Each approved report is valid for two (2) years from its issue date

● ISVs that fail to comply by the required deadline may face restricted access to PII, impacting PII-dependent features and workflows

● Submission Deadline: 1 March 2026

  1. Why can’t I see the ‘Add’ entry in Account Information?

A: Please ensure you are logged in to the Open Platform Console using a developer account. Member accounts have view-only access and cannot edit or upload documents

----------------------------------------------------------------------------------------------------------------------

【政策更新】渗透测试报告提交迁移至Open Platform Console

尊敬的第三方合作伙伴平台(ISV)开发人员:

我们在此通知您,Shopee Open Platform 数据保护政策(DPP)下的渗透测试报告提交流程已更新。

为提升提交可见性、审核效率及整体开发者体验,Shopee 将 渗透测试报告的提交渠道由邮件迁移至 Open Platform Console 。

对开发者的影响

即日起,所有渗透测试报告必须通过 Shopee Open Platform Console 提交,不再接受通过邮件提交的报告。

曾通过邮件或 Open Platform Console 提交过报告的开发者,需要在 Open Platform Console 中重新提交一次

本次更新带来的改进:

● 您可以在同一平台查看提交状态、审核结果和过期提醒

● 集中管理报告的有效期与续期记录

● 支持在 Open Platform Console 中上传多份安全相关文件(例如渗透测试报告、ISO/IEC 27001 证书、SOC 2 II 型报告),取代了以前单个文档的限制

🔔重要说明:本次更新 仅涉及提交方式的变更,所有现有的政策要求、有效期规则及审核标准 均保持不变。

最新提交指引

如何提交渗透测试报告:

● 步骤 1:使用 developer account 登录 Open Platform Console。

注意:member account没有上传报告的权限。

● 步骤 2:前往Personal Center → Account Information (中国大陆ISV:地址链接,其他地区ISV:地址链接

● 步骤 3:在Security Reports & Certifications Information 点击“Add”

● 步骤 4:在“Security Report & Certification Type”下,选择 “Penetration Test Report”

● 步骤 5:上传您最新的渗透测试报告

● 步骤 6:点击 “Save“

审核周期

● 提交状态(通过 / 拒绝)将显示在「Account Information」页面

● 审核结果通常在 10 个工作日 内更新

常问问题

  1. 如果我已经通过电子邮件发送了我的渗透测试报告怎么办?

回答:Shopee OpenAPI 团队非常感谢此前按要求通过邮件提交报告的开发者。

为统一新的提交流程,您仍需通过 Open Platform Console 重新提交一次报告。邮件提交的报告将不再纳入新流程审核。

若您的报告此前已通过邮件审核,且仍在有效期内,在 Console 中重新提交后将再次获批。

  1. 如果我已经将渗透测试报告上传到开放平台控制台了怎么办?

回答:由于系统升级,部分历史上传的安全文件未能完整迁移。为确保您的信息完整、最新,仍需重新提交。

  1. 渗透测试报告提交政策是否有任何变化?文件必须在何时提交?

回答:与之前公布的内容相比,没有任何变化。对于为 泰国卖家(TH)提供服务,且需要在必须场景下访问buyer 个人信息的 ISV,这是强制要求。

● 每份通过审核的报告 自出具日起,有效期为 2 年

● 未在截止时间前合规的 ISV,可能会被限制 PII 访问权限,影响相关功能和流程

● 提交截止日期:2026年3月1日

  1. 为什么我在Account Information中看不到“Add” 按钮?
#