Vulnerability Disclosure Policy
Last updated: August 19, 2026
Our commitment
ShadowPOS values the work of security researchers who help us protect our customers and systems. This policy explains how to report a suspected vulnerability and the rules for good-faith security research.
If you believe you have found a security vulnerability, email us at security@shadowpos.com. Please do not send vulnerability reports through sales, support, or social media channels.
What to include
A useful report includes:
- The affected product, hostname, URL, feature, or API endpoint
- A clear description of the vulnerability and its potential impact
- Reproducible steps, including relevant requests, responses, screenshots, or code
- Any conditions required to reproduce the issue
- Your name or handle if you would like acknowledgment
Remove passwords, access tokens, payment information, customer data, and other unnecessary personal or sensitive information from your report.
Scope
This policy covers publicly accessible websites, applications, and APIs owned and operated by ShadowPOS, including services on shadowpos.com and its subdomains.
The following are out of scope:
- Customer-owned domains, networks, accounts, devices, data, and storefront content
- Third-party products, integrations, payment processors, and services
- Employee, contractor, or customer devices and physical locations
- Findings that only identify missing best-practice headers without a demonstrated security impact
- Automated scanner output without evidence that the finding is reproducible
If you are unsure whether a system is in scope, contact us before testing it.
Research guidelines
When conducting research:
- Use only accounts and data you own or have explicit permission to use.
- Make a good-faith effort to avoid privacy violations, data loss, and service disruption.
- Stop testing and notify us immediately if you encounter customer data or gain unintended access.
- Access only the minimum data necessary to demonstrate the vulnerability.
- Do not retain, copy, download, alter, destroy, or disclose data that is not yours.
- Give us a reasonable opportunity to investigate and remediate before publicly disclosing the issue.
Prohibited testing
This policy does not authorize:
- Denial-of-service, load testing, or activity that degrades availability
- Social engineering, phishing, spam, credential stuffing, or password spraying
- Physical security testing or attempts to access offices, stores, hardware, or employee devices
- Malware, persistence, destructive actions, or modification of production data
- High-volume automated scanning or traffic that may affect other users
- Testing payment terminals, payment-card data, or third-party systems
- Extortion, threats, or conditioning disclosure on payment
What you can expect
We aim to:
- Acknowledge your report within three business days.
- Provide an initial assessment or request additional information within ten business days.
- Keep you reasonably informed while we investigate and remediate a confirmed issue.
- Coordinate the timing and content of any public disclosure with you.
Response and remediation times vary based on complexity, severity, and operational constraints. These are targets, not guarantees.
Safe harbor
When you conduct research in good faith and comply with this policy, we will consider your activity authorized for purposes of this policy and will not initiate or recommend legal action against you for that research. If we believe your activity presents an immediate risk to customers, data, or service availability, we may ask you to stop.
We cannot authorize research on third-party systems and cannot bind third parties, prosecutors, or law enforcement. You are responsible for complying with applicable law. If you have concerns about whether a planned test is permitted, contact us before proceeding.
Recognition and compensation
ShadowPOS does not currently operate a bug bounty program. Submitting a report does not create a contract or entitlement to payment, reward, reimbursement, or other compensation. We may choose to recognize a researcher, with their permission, but recognition and compensation are entirely at our discretion.
Please report vulnerabilities because you want to help protect ShadowPOS and its users, not with an expectation of payment.
Report a vulnerability
Email security@shadowpos.com with the subject line Security vulnerability report.