Responsible Disclosure Policy
Version 1.8 · effective September 24, 2025
Keeping our customers' data safe is our top priority at Shopxare, LLC. If you believe you have found a security vulnerability, we want to hear from you.
1. How to report
Use the vulnerability report form or email [email protected] with the subject "Security". Please include:
- a description of the vulnerability and its potential impact;
- steps to reproduce it, including URLs, requests and any proof-of-concept code;
- your name or handle, if you would like to be credited.
2. Scope
In scope: shopxare.com, app.shopxare.com (the web app, the Messenger, the help centers, the REST API, the MCP server), the Shopxare desktop and mobile apps, and our plugins and SDKs.
Out of scope:
- websites of our customers (please report those to the customer);
- third-party services we use (report to the provider);
- denial-of-service tests, spam, and social engineering or phishing of our staff or customers;
- physical attacks on offices or data centers;
- findings from automated scanners without a demonstrated impact;
- missing best-practice headers or cookie flags without a demonstrated security impact;
- clickjacking on pages without sensitive actions;
- rate-limit or brute-force findings on non-authentication endpoints;
- vulnerabilities only exploitable on outdated browsers or rooted/jailbroken devices.
3. Rules of engagement
- Use only test Workspaces you created yourself. Do not access, modify or delete data of other users; if you accidentally access such data, stop, do not keep it, and tell us.
- Do not degrade the Services for others.
- Do not publicly disclose the vulnerability until we have fixed it or 90 days have passed since your report, whichever comes first, unless we agree otherwise.
4. Our promise
If you follow this policy, we will:
- confirm receipt within 3 business days and keep you informed;
- not take legal action against you or ask authorities to do so for your research, and consider it authorised under applicable anti-hacking laws;
- work with you to understand and fix the issue;
- credit you publicly, if you wish, once the issue is fixed.
We do not currently run a paid bug bounty programme, but we may reward significant findings at our discretion.