SECURITY AND RESPONSIBLE DISCLOSURE
Last Updated: July 30, 2026
SECURITY AT SILEASY
SILEASY LLC takes the security of Sileasy Brands, merchant information, and our supporting infrastructure seriously.
We welcome responsible reports from researchers, merchants, and other users who believe they have identified a security vulnerability.
REPORT A SECURITY ISSUE
Send reports to:
security@sileasy.com
Please use a clear subject line such as:
Security Report — Sileasy Brands
INFORMATION TO INCLUDE
When possible, include:
- A clear description of the suspected vulnerability.
- The affected Sileasy service, page, route, or feature.
- The conditions required to reproduce the issue.
- Step-by-step reproduction instructions.
- The potential security or privacy impact.
- Screenshots, recordings, or proof-of-concept material that do not contain unnecessary personal information.
- Your preferred contact information.
- Whether you believe the issue is being actively exploited.
DO NOT INCLUDE
Please do not send:
- Shopify access tokens.
- Session tokens.
- Partner API tokens.
- Database credentials.
- Passwords.
- Payment-card information.
- Customer personal information.
- Information belonging to another merchant.
If sensitive information is necessary to demonstrate an issue, contact us first so that we can arrange an appropriate method of transmission.
RESPONSIBLE TESTING
Do not:
- Access, modify, or delete data belonging to another merchant.
- Attempt to bypass Shopify authentication using another store.
- Exfiltrate personal information.
- Perform denial-of-service or resource-exhaustion testing.
- Send excessive automated requests.
- Upload malware.
- Conduct social-engineering, phishing, or physical-security attacks.
- Test third-party services such as Shopify, Render, Neon, WordPress, email providers, or domain providers without their authorization.
- Disrupt a production storefront.
- Publicly disclose an unresolved issue before giving us a reasonable opportunity to investigate.
REPORT HANDLING
After receiving a report, we aim to:
- Acknowledge receipt within five business days.
- Review whether the issue affects Sileasy-controlled systems.
- Request additional information when necessary.
- Assess severity and potential impact.
- Develop and validate an appropriate remediation.
- Coordinate disclosure when appropriate.
These timeframes are targets and are not guaranteed service-level commitments.
ELIGIBLE REPORTS
Examples of reports that may be relevant include:
- Authentication or authorization bypass.
- Cross-store or cross-tenant data access.
- Exposure of application secrets or tokens.
- Injection vulnerabilities.
- Cross-site scripting in Sileasy-controlled application surfaces.
- Server-side request forgery.
- Insecure direct-object references.
- Incorrect App Proxy signature validation.
- Incorrect webhook verification.
- Unauthorized Premium entitlement.
- Data deletion or privacy failures.
- Vulnerabilities in Sileasy-controlled infrastructure.
GENERALLY OUT OF SCOPE
Examples that are generally outside our control include:
- Shopify platform vulnerabilities.
- Issues in unsupported or modified third-party themes.
- Missing security headers without a demonstrated exploitable impact.
- Reports based only on automated scanner output without reproduction or impact.
- Previously reported issues already under investigation.
- Social-engineering attacks.
- Denial-of-service testing.
- Findings that require physical access to a user’s device.
- Issues in software or services not controlled by SILEASY LLC.
NO BUG BOUNTY PROGRAM
SILEASY LLC does not currently operate a paid bug bounty program.
Submitting a report does not create a right to compensation, reward, public recognition, or employment.
We may acknowledge helpful researchers at our discretion and only with their permission.
PRIVACY
Information submitted in a security report will be used to investigate, remediate, document, and communicate about the reported issue.
Do not include more personal information than necessary.
Privacy questions may be sent to:
privacy@sileasy.com
LEGAL NOTICE
Nothing on this page authorizes activity that violates applicable law, Shopify policies, contracts, or the rights of third parties.
Responsible disclosure does not authorize destructive testing or access to data that you do not own or control.
CONTACT
SILEASY LLC
Wyoming, United States
Security:
security@sileasy.com
Support:
support@sileasy.com
Website: