Security & Responsible Disclosure

How to report a vulnerability in ShipShield.

Last updated: October 10, 2026

Contents

Reporting a vulnerability

We build a security product, so we take reports about our own security seriously. If you believe you have found a vulnerability in ShipShield, email support@shipshield.dev with a clear description and steps to reproduce it.

Scope

  • In scope: shipshield.dev and its API.
  • Out of scope: denial-of-service, spam or social engineering, physical attacks, and issues in third-party services we use.

Guidelines

  • Do not access, change or delete data that is not yours.
  • Stop testing and tell us right away if you reach sensitive data.
  • Give us reasonable time to fix the issue before sharing it publicly.

Safe harbor

If you act in good faith and follow these guidelines, we will not pursue legal action against you for your research. We will acknowledge your report and keep you updated as we work on a fix.