Security

Found a hole? Tell us about it.

We sell a pen and we run a small web app, and both of them are code somebody could break. This page says what we would like you to test, what we would rather you left alone, and what we promise in return for a report made in good faith.

Report it

Send us the details.

Everything in one place, so the first reply can be an answer rather than four more questions. It lands in the same inbox as [Security email], and a person reads it.

This is ordinary email underneath, so keep other people's personal data out of it. If the detail is too sensitive for an unencrypted message, send a summary and we will agree a channel in the reply.

Anything to do with Shopify's checkout, accounts or infrastructure belongs with Shopify's programme rather than here.

  1. You report it privatelyThrough this form or by email, one issue at a time.
  2. We acknowledge itWithin three working days, from the person who is looking at it.
  3. We assess itWithin ten working days: whether we could reproduce it, and how serious we think it is.
  4. We fix it, and you take the creditYou hear when the fix ships. Publish after ninety days, or sooner if we agree it — with your name on it if you want it.

This is how we would credit you.

The checkout is Shopify's. Tell us anyway and we will pass it on.

Your estimate. We make our own, and say so if we disagree.

Sent straight to our inbox. Covered by the safe harbour above.

Credit where it is due

The people who told us first.

Researchers who reported something here and asked to be named are listed on this page. Nobody is listed yet. We would rather write that than invent a hall of fame, and the first name goes up the day it is earned.

Not a security issue? A bug in the app or a problem with an order goes to the contact page. A question about your own data goes to the privacy policy. Something on the site that stopped you using it belongs on the accessibility page — those reports are read with the same seriousness as these.