SILEASY SECURITY
Security and Responsible Disclosure
Guidance for merchants, researchers, and users who believe they have identified a security vulnerability affecting a Sileasy-controlled service. Last UpdatedAugust 21, 2026 Security Contact security@sileasy.com
SECURITY AT SILEASY
Protecting merchants and Sileasy-controlled systems
SILEASY LLC takes the security of the Sileasy website, Sileasy Brands, Sileasy Stock Flow, future Sileasy applications, merchant information, and our supporting infrastructure seriously.
We welcome responsible reports from researchers, merchants, partners, and other users who believe they have identified a security vulnerability in a system or service controlled by SILEASY LLC.
Please avoid accessing data that you do not own or control. Stop testing and contact us immediately if you encounter another merchant’s information, credentials, tokens, or personal data. 01
Sileasy Website
Security issues affecting Sileasy-controlled pages, forms, and web services.
Sileasy Brands
Security issues in the embedded app, brand-directory features, and Sileasy-controlled storefront components.
Sileasy Stock Flow
Security issues involving inventory workflows, automation, collection ordering, publications, or app access.
Future Sileasy Apps
Additional applications and services operated by SILEASY LLC that link to this policy.
REPORT A SECURITY ISSUE
Email our security team
Send a clear, detailed report to the address below. Security reports should not be sent to public forums, app reviews, social media, or unrelated support channels. security@sileasy.com
SUGGESTED SUBJECT
Use the product or service name whenever possible:
Security Report — Sileasy BrandsSecurity Report — Sileasy Stock FlowSecurity Report — Sileasy Website
1. Information to Include
When possible, include:
- A clear description of the suspected vulnerability.
- The affected Sileasy service, application, page, route, workflow, or feature.
- The Shopify store type involved, such as a development store or merchant-controlled store.
- The conditions required to reproduce the issue.
- Step-by-step reproduction instructions.
- The result you expected and the result you observed.
- The potential security, privacy, billing, or merchant impact.
- Whether the issue appears to affect one store, multiple stores, or an unauthenticated user.
- Screenshots, recordings, logs, or proof-of-concept material that do not contain unnecessary sensitive information.
- Your preferred contact information.
- Whether you believe the issue is being actively exploited.
A concise proof of concept is helpful, but it should use the minimum access, requests, and data necessary to demonstrate the issue safely.
2. Do Not Include Sensitive Information
Please do not send:
- Shopify access tokens.
- Session tokens or cookies.
- Shopify Partner API tokens.
- Internal runner or automation secrets.
- Database credentials or connection strings.
- Passwords or recovery codes.
- Payment-card or banking information.
- Customer personal information.
- Information belonging to another merchant.
- Unredacted production logs containing secrets or personal data.
Need to share sensitive evidence? Contact us first with a non-sensitive summary so that we can determine an appropriate transmission method. Do not email live credentials, tokens, or another merchant’s data.
3. Responsible Testing
Security testing must be limited to accounts, development stores, data, and systems that you own or are expressly authorized to test. Use low-impact methods and stop when you have enough evidence to explain the issue.
Do not:
- Access, modify, publish, hide, reorder, or delete data belonging to another merchant.
- Attempt to authenticate as another store or bypass Shopify authentication using another merchant’s identity.
- Exfiltrate personal information, store data, credentials, tokens, secrets, or configuration.
- Create, approve, alter, or dispute subscription charges without authorization.
- Perform denial-of-service, stress, load, rate-limit exhaustion, or resource-exhaustion testing.
- Send excessive automated requests, webhook traffic, background jobs, or App Proxy requests.
- Upload malware, destructive code, or persistent payloads.
- Conduct social-engineering, phishing, credential-stuffing, or physical-security attacks.
- Test Shopify, Render, Neon, WordPress, email providers, domain providers, or other third-party services without their authorization.
- Disrupt a production storefront, Shopify Admin workflow, collection, publication, search experience, or merchant automation.
- Modify production data beyond the minimum necessary in a store you control.
- Publicly disclose an unresolved issue before giving Sileasy a reasonable opportunity to investigate and respond.
If testing unexpectedly exposes another merchant’s information or affects a production service, stop immediately, preserve only the minimum evidence needed, and notify us at security@sileasy.com.
4. Report Handling
After receiving a report, we aim to:
- Acknowledge the report. Our target is to acknowledge receipt within five business days.
- Confirm scope. We review whether the issue affects a Sileasy-controlled system or should be reported to a third party.
- Request clarification. We may ask for additional reproduction details, redacted evidence, or environmental information.
- Assess impact. We evaluate severity, exploitability, affected merchants, data exposure, and operational impact.
- Remediate and validate. Where appropriate, we develop, test, deploy, and verify a remediation.
- Coordinate communication. We may coordinate disclosure, merchant notification, or third-party reporting when appropriate.
These timeframes and steps are operational targets and are not guaranteed service-level commitments. Complex issues, third-party dependencies, active incidents, or legal obligations may require additional time.
5. Eligible Reports and Security Scope
Examples of reports that may be relevant include:
- Authentication or authorization bypass affecting a Sileasy-controlled service.
- Cross-store, cross-tenant, or unauthorized merchant data access.
- Exposure of application secrets, tokens, credentials, or sensitive configuration.
- Injection vulnerabilities.
- Cross-site scripting in Sileasy-controlled application surfaces.
- Server-side request forgery.
- Insecure direct-object references.
- Incorrect Shopify webhook authentication or request verification.
- Incorrect App Proxy request verification in a Sileasy-controlled implementation.
- Unauthorized access to paid functionality or manipulation of verified plan entitlements.
- Privacy-request, deletion, redaction, or data-isolation failures.
- Vulnerabilities in Sileasy-controlled infrastructure with a demonstrated security impact.
SILEASY BRANDS
Examples of relevant app-specific issues
- Unauthorized access to another store’s brand or vendor configuration.
- Improper validation of Sileasy-controlled storefront or App Proxy requests.
- Stored or reflected script execution in Sileasy-controlled brand fields or interfaces.
- Unauthorized activation of plan-restricted brand-directory functionality.
- Exposure of merchant-uploaded brand assets or destinations through an access-control failure.
SILEASY STOCK FLOW
Examples of relevant app-specific issues
- Unauthorized inventory, collection, publication, or search-visibility actions.
- Cross-store access to jobs, webhooks, activity, settings, or automation state.
- Authentication or authorization failures affecting internal or merchant-triggered operations.
- Entitlement bypass that enables plan-restricted commercial actions.
- Security failures that allow an unauthorized party to alter collection ordering or product visibility.
- Privacy or lifecycle failures following uninstall, data requests, or redaction events.
WEBSITE AND FUTURE APPS
Additional Sileasy-controlled services
Reports involving the Sileasy website or a future Sileasy application are eligible when they demonstrate a reproducible security or privacy impact in a system operated or controlled by SILEASY LLC.
6. Generally Out of Scope
Examples that are generally outside our control or not actionable under this policy include:
- Shopify platform vulnerabilities or billing-system vulnerabilities that do not originate in Sileasy-controlled code.
- Issues in Render, Neon, WordPress, email, DNS, domain, browser, operating-system, or other third-party services that are not caused by Sileasy-controlled configuration or code.
- Issues in unsupported, outdated, or heavily modified third-party Shopify themes.
- Third-party applications, scripts, custom code, or integrations not operated by SILEASY LLC.
- Missing security headers or configuration best-practice observations without a demonstrated exploitable impact.
- Reports based only on automated scanner output without clear reproduction steps and impact.
- Self-XSS or behavior requiring a user to paste attacker-controlled code into a developer console without another security boundary being crossed.
- Previously reported issues already under investigation or already remediated.
- Social-engineering, phishing, physical-security, denial-of-service, or resource-exhaustion testing.
- Findings that require physical access to a user’s device or prior compromise of the user’s account or device.
- Product bugs, availability problems, or support questions without a security or privacy impact.
- Issues in software or systems not controlled by SILEASY LLC.
General bugs, billing questions, and availability reports should be sent to support@sileasy.com instead of the security mailbox.
7. Coordinated Disclosure and Confidentiality
Please give Sileasy a reasonable opportunity to investigate and remediate a reported issue before publishing technical details, proof-of-concept material, screenshots, exploit instructions, or information that could place merchants or systems at risk.
We may ask you to delay disclosure while remediation, merchant protection, third-party coordination, or legal notification is underway. We will make reasonable efforts to communicate status when appropriate, but we may be unable to share confidential implementation details, merchant information, investigation records, or third-party communications.
Public recognition of a reporter, researcher, or organization will occur only at Sileasy’s discretion and with the reporter’s permission.
8. No Bug Bounty Program
SILEASY LLC does not currently operate a paid bug bounty program.
Submitting a report does not create a right to payment, compensation, reward, reimbursement, public recognition, employment, or any other benefit.
We may acknowledge a helpful researcher at our discretion and only with that person’s permission.
9. Privacy
Information submitted in a security report may be used to receive, investigate, reproduce, remediate, document, and communicate about the reported issue; protect merchants and systems; comply with legal obligations; and coordinate with affected service providers where necessary.
Do not include more personal information than is reasonably necessary.
Privacy questions and personal-data requests may be sent to privacy@sileasy.com. Additional information is available in the Sileasy Privacy Policy.
10. Legal Notice
Nothing on this page grants permission to violate applicable law, Shopify policies, contracts, access restrictions, intellectual-property rights, privacy rights, or the rights of third parties.
Responsible disclosure does not authorize destructive testing, service disruption, access to information that you do not own or control, impersonation of another merchant, or testing of third-party services without authorization.
This policy does not create a contract for compensation, a service-level agreement, or a guarantee that a report will qualify as a vulnerability. Sileasy may update this policy as our Services, security practices, or legal obligations evolve.
CONTACT
11. Contact Sileasy
Use the security address for vulnerability reports and the support address for general product assistance.
Company
SILEASY LLC
Wyoming, United States sileasy.com
Security reports security@sileasy.com
Support support@sileasy.com
Privacy requests privacy@sileasy.com
Legal inquiries legal@sileasy.com