Security and Responsible Disclosure

SECURITY AND RESPONSIBLE DISCLOSURE

Last Updated: July 30, 2026

SECURITY AT SILEASY

SILEASY LLC takes the security of Sileasy Brands, merchant information, and our supporting infrastructure seriously.

We welcome responsible reports from researchers, merchants, and other users who believe they have identified a security vulnerability.

REPORT A SECURITY ISSUE

Send reports to:

security@sileasy.com

Please use a clear subject line such as:

Security Report — Sileasy Brands

INFORMATION TO INCLUDE

When possible, include:

  • A clear description of the suspected vulnerability.
  • The affected Sileasy service, page, route, or feature.
  • The conditions required to reproduce the issue.
  • Step-by-step reproduction instructions.
  • The potential security or privacy impact.
  • Screenshots, recordings, or proof-of-concept material that do not contain unnecessary personal information.
  • Your preferred contact information.
  • Whether you believe the issue is being actively exploited.

DO NOT INCLUDE

Please do not send:

  • Shopify access tokens.
  • Session tokens.
  • Partner API tokens.
  • Database credentials.
  • Passwords.
  • Payment-card information.
  • Customer personal information.
  • Information belonging to another merchant.

If sensitive information is necessary to demonstrate an issue, contact us first so that we can arrange an appropriate method of transmission.

RESPONSIBLE TESTING

Do not:

  • Access, modify, or delete data belonging to another merchant.
  • Attempt to bypass Shopify authentication using another store.
  • Exfiltrate personal information.
  • Perform denial-of-service or resource-exhaustion testing.
  • Send excessive automated requests.
  • Upload malware.
  • Conduct social-engineering, phishing, or physical-security attacks.
  • Test third-party services such as Shopify, Render, Neon, WordPress, email providers, or domain providers without their authorization.
  • Disrupt a production storefront.
  • Publicly disclose an unresolved issue before giving us a reasonable opportunity to investigate.

REPORT HANDLING

After receiving a report, we aim to:

  • Acknowledge receipt within five business days.
  • Review whether the issue affects Sileasy-controlled systems.
  • Request additional information when necessary.
  • Assess severity and potential impact.
  • Develop and validate an appropriate remediation.
  • Coordinate disclosure when appropriate.

These timeframes are targets and are not guaranteed service-level commitments.

ELIGIBLE REPORTS

Examples of reports that may be relevant include:

  • Authentication or authorization bypass.
  • Cross-store or cross-tenant data access.
  • Exposure of application secrets or tokens.
  • Injection vulnerabilities.
  • Cross-site scripting in Sileasy-controlled application surfaces.
  • Server-side request forgery.
  • Insecure direct-object references.
  • Incorrect App Proxy signature validation.
  • Incorrect webhook verification.
  • Unauthorized Premium entitlement.
  • Data deletion or privacy failures.
  • Vulnerabilities in Sileasy-controlled infrastructure.

GENERALLY OUT OF SCOPE

Examples that are generally outside our control include:

  • Shopify platform vulnerabilities.
  • Issues in unsupported or modified third-party themes.
  • Missing security headers without a demonstrated exploitable impact.
  • Reports based only on automated scanner output without reproduction or impact.
  • Previously reported issues already under investigation.
  • Social-engineering attacks.
  • Denial-of-service testing.
  • Findings that require physical access to a user’s device.
  • Issues in software or services not controlled by SILEASY LLC.

NO BUG BOUNTY PROGRAM

SILEASY LLC does not currently operate a paid bug bounty program.

Submitting a report does not create a right to compensation, reward, public recognition, or employment.

We may acknowledge helpful researchers at our discretion and only with their permission.

PRIVACY

Information submitted in a security report will be used to investigate, remediate, document, and communicate about the reported issue.

Do not include more personal information than necessary.

Privacy questions may be sent to:

privacy@sileasy.com

LEGAL NOTICE

Nothing on this page authorizes activity that violates applicable law, Shopify policies, contracts, or the rights of third parties.

Responsible disclosure does not authorize destructive testing or access to data that you do not own or control.

CONTACT

SILEASY LLC

Wyoming, United States

Security:

security@sileasy.com

Support:

support@sileasy.com

Website: