IoneShop
For companies & multi-storeOpen Enterprise

Security

Vulnerability Disclosure Policy

This policy describes how independent security researchers may report vulnerabilities in IoneShop platform surfaces operated by ABSGROUP INC. It is a Vulnerability Disclosure Program (VDP) — recognition and coordinated remediation, not a paid bug bounty.

This text is an operational policy, not legal advice. Safe-harbor expectations below apply only to good-faith research within scope.

1. How to report

Email [email protected] with:

  1. A clear description of the issue and affected URL / host / endpoint
  2. Steps to reproduce (or a minimal proof of concept)
  3. Impact assessment (what an attacker could achieve)
  4. Your contact details
  5. Whether you want public acknowledgment after a fix

Do not include real shopper PII, payment card data, or production secrets beyond what is strictly needed for the PoC. Redact where possible.

Please submit reports in English.

2. Our commitments

StepTarget
AcknowledgementWithin 5 business days
Initial triage / severity viewWithin 10 business days of acknowledgement
Status updateAt least every 30 days until resolved or closed

Timelines may extend for complex multi-tenant issues. We will not publicly discuss an open report without coordinating with you, except where legally required.

After a fix (or an agreed closing decision), we may list a short acknowledgment on this page or in release notes if you opt in.

3. In scope

Only assets we operate as the IoneShop platform:

In-scope classes (examples): authentication/session flaws, broken access control, cross-tenant data exposure, SSRF against platform services, injection on platform apps, serious misconfiguration exposing platform secrets.

4. Out of scope

5. Rules of engagement

6. Safe harbor (good-faith research)

If you follow this policy, stay in scope, and avoid privacy harm beyond a minimal PoC, we will:

Safe harbor does not cover out-of-scope activity, extortion, public disclosure before we have a reasonable chance to remediate, or violation of law.

7. Future managed program

We may later move intake to a managed VDP platform (e.g. Intigriti, YesWeHack, or HackerOne). If we do, security.txt and this page will be updated with the canonical submission URL. Until then, email is the channel of record.

Related documents

← Back to IoneShop

Vulnerability disclosure · IoneShop