Security and vulnerability reporting
Merchants trust Securify and OTP+ with their storefront traffic and their customers' data. If you find a weakness in either app, tell us. We will confirm it, fix it on the timelines below and keep you updated until it is closed.
How to report a security issue
Email [email protected] with the subject “Security report”. Please include:
- which app or page is affected, and its URL
- the steps to reproduce the issue
- what an attacker could do with it
- how we can reach you for follow-up questions
Please share only the data needed to show the problem. If you come across personal data of a merchant or a shopper, stop, do not keep a copy, and tell us in your report.
What happens after you report
- We confirm we received your report within 2 business days.
- We assess it and tell you the severity we assigned within 5 business days.
- We fix it within the target for its severity, counted from the moment we confirm the issue, and tell you when the fix is live.
Fix timelines by severity
We rate severity with the Common Vulnerability Scoring System (CVSS) and the real impact on stores and shoppers.
| Severity | CVSS score | What it means | Fixed within |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Someone could read or change another store's data, or take over an account, without any help from the victim. | 24 hours |
| High | 7.0 – 8.9 | Sensitive data or an account is exposed, but only under specific conditions. | 7 days |
| Medium | 4.0 – 6.9 | Limited exposure, or the attack needs the victim to take an unusual step. | 30 days |
| Low | 0.1 – 3.9 | Little or no impact on store or customer data. | 30 days |
What this covers
- Securify, the Shopify app (admin app, storefront app embed and checkout protection)
- OTP+, the Shopify app (customer sign-in with one-time codes and social login)
- securification.ai and the services behind both apps
Issues in Shopify itself belong to Shopify's own program.
Rules for testing
- Test the Shopify apps only on a development store you own. Never test against a live merchant's store.
- Do not read, change or delete data that is not yours.
- No denial-of-service or load testing, spam, social engineering of our team or merchants, or physical attacks.
- Give us a reasonable time to fix the issue before you share it publicly.
If you follow these rules in good faith, we will not pursue or support legal action against you for your research.
Usually out of scope
- Automated scanner output without a working example of impact
- Missing best-practice headers or settings with no demonstrated impact
- Bugs in third-party services we use, unless our setup causes them
Recognition
We do not run a paid bug bounty. With your permission, we are glad to credit you once the fix is live.
For machines
This contact is also published in /.well-known/security.txt (RFC 9116).