SHIPR POLICY
Security & Vulnerability Disclosure Policy
How to report a security vulnerability in Shipr, the rules for testing, what we will do in response, and our good-faith safe harbor for researchers.
1. Reporting a Vulnerability
We welcome reports from anyone who finds a security vulnerability in Shipr systems. Email support@shiprsolutions.com with "Security report" in the subject line, a description of the issue, the steps to reproduce it, and the affected web address or app version. Please include no more personal information than you need to demonstrate the issue.
2. Testing Rules
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption of service.
- Test only against accounts you own or have permission to use.
- Do not access, change, keep, or share other people's data. If you encounter it, stop and tell us.
- Do not use denial-of-service attacks, spam, social engineering, or physical attacks.
- Give us a reasonable time to fix the issue before you disclose it publicly.
3. What We Will Do
We will acknowledge your report, keep you informed as we investigate, and, if you wish, credit you once the issue is fixed. We do not currently offer monetary rewards.
4. Safe Harbor
If you follow this Policy in good faith, we will consider your research authorized, we will not pursue legal action against you for it, and we will not ask law enforcement to do so. This Policy cannot authorize testing of systems we do not own, such as our service providers.
5. Out of Scope
- Systems run by our service providers (for example, our sign-in, payment, mapping, and background-check providers); report those to the provider.
- Findings that require a compromised or rooted device.
- Missing security headers or best-practice settings without a demonstrated security impact.
- Volumetric, denial-of-service, and automated scanning traffic.