来自 Shopee 官方资料快照 ·
- 当前资料结构化阅读页
- 固定快照已留存,可追溯
- 官方原文可核对
资料正文
§1 Mandatory Penetration Test Report Submission for Buyer PII Access
Applicable to ISVs from China Cross-Border (CNCB), Hong Kong Cross-Border (HKCB), and ISVs supporting sellers in Singapore, Malaysia, and the Philippines
Dear Third-party Partner Platform Developers (ISVs),
We would like to inform you of an important update to the Shopee Open Platform Data Protection Policy (DPP).
Following the implementation of the mandatory Penetration Test Report submission policy for Third-party Partner Platform Developers (ISVs) supporting Thailand sellers, Shopee is extending this requirement to additional ISVs as part of our ongoing commitment to strengthening data protection and safeguarding buyers' Personally Identifiable Information (PII).
This policy will now apply to the following ISVs who are serving sellers require access to buyer PII:
● ISVs from China Cross-Border (CNCB),
● ISVs from Hongkong Cross-Border (HKCB),
● ISVs supporting Malaysia sellers,
● ISVs supporting Singapore sellers,
● ISVs supporting Philippines sellers
Policy Effective Date
Starting 13 July 2026, all applicable ISVs must submit a valid Penetration Test Report to obtain or maintain access to buyer PII.
Each approved report will remain valid for two (2) years from its issue date.
ISVs that fail to comply by 31 August 2026 may have their access to buyer PII restricted, which may impact any features, functionalities, or workflows that rely on sensitive buyer information.
Please note that the APIs will continue to function. However, buyer PII fields—including, but not limited to, the customer's name, phone number, email address, and delivery address—may be masked in the API responses.
Requirements for ISVs
- For New ISVs:
ISVs registering on or after 13 July 2026 must:
○ Submit a valid and recent Penetration Test Report during the onboarding process.
○ Buyer PII access will only be granted after the report has been successfully reviewed and approved.
- For Existing ISVs:
ISVs that currently have access to buyer PII must submit a valid Penetration Test Report by 31 August 2026 to maintain uninterrupted access.
To avoid disruptions to PII-dependent operations, reports must be renewed every two (2) years from the report's issue date.
How to Submit Your Penetration Test Report
To submit your Penetration Test Report:
Step 1: Log in to your Open Platform console using your developer account
Note: Member accounts do not have permission to upload reports.
Step 2: Navigate to Personal Center → Account Information (Chinese Mainland ISVs: Link, Other Region ISVs: Link)
Step 3: Under Security Reports & Certifications Information, click "Add"
Step 4: Under Security Report & Certification Type, Choose “Penetration Test Report”
Step 5: Upload your latest penetration test report
Step 6: Click “Save”
Review results are typically available within 10 working days and will be displayed in the Account Information section.
Good Practices for Penetration Test Report Submission:
To facilitate timely review and approval, we recommend engaging penetration testers with recognized industry certifications, including:
● CREST Accredited Penetration Tester
● Offensive Security Certified Professional (OSCP)
● GIAC Certified Penetration Tester (GPEN)
● Certified Ethical Hacker (CEH)
● Certified Information Systems Security Professional (CISSP)
● EC-Council Certified Security Analyst (ECSA)
● CompTIA PenTest+
● AWS Security Competency Partners
● Alibaba Cloud Security Partners
● Qianxin (奇安信)
● 360 数字安全
● Sangfor (深信服)
● Chaitin (长亭科技)
Reports prepared by other qualified penetration testing providers will also be reviewed and approved on a case-by-case basis.
Report Quality Requirements
A complete Penetration Test Report should:
-
Cover the application's externally exposed attack surface.
-
Assess all relevant systems and applications within the testing scope.
-
Document the testing methodology, testing process, scope, and detailed findings.
-
Include a comprehensive list of identified vulnerabilities.
-
Confirm that all Critical and High severity vulnerabilities have been remediated.
-
Be based on black-box penetration testing.
Please note: Vulnerability scan reports alone are not acceptable and will not satisfy this requirement.
Recommended Report Recency
We recommend submitting a report issued within the last one (1) year.
Although an approved report remains valid for two (2) years from its issue date, submitting a more recent report allows you to maximize the validity period for buyer PII access.
For any questions or further clarification, feel free to contact us by raising an Open Platform Ticket here or contact the Open Platform Support Team at openapi-noti@shopee.com
Thank you for your continued cooperation and support in helping us maintain a secure, trusted, and compliant ecosystem for all Shopee sellers and users.
Best regards,
Shopee OpenAPI Team
