Security
Vulnerability Disclosure Policy
- Version: 1.1
- Effective date: 2026-08-03
- Contact: [email protected]
- Machine-readable: [/.well-known/security.txt](/.well-known/security.txt)
This policy describes how independent security researchers may report vulnerabilities in IoneShop platform surfaces operated by ABSGROUP INC. It is a Vulnerability Disclosure Program (VDP) — recognition and coordinated remediation, not a paid bug bounty.
This text is an operational policy, not legal advice. Safe-harbor expectations below apply only to good-faith research within scope.
1. How to report
Email [email protected] with:
- A clear description of the issue and affected URL / host / endpoint
- Steps to reproduce (or a minimal proof of concept)
- Impact assessment (what an attacker could achieve)
- Your contact details
- Whether you want public acknowledgment after a fix
Do not include real shopper PII, payment card data, or production secrets beyond what is strictly needed for the PoC. Redact where possible.
Please submit reports in English.
2. Our commitments
| Step | Target |
|---|---|
| Acknowledgement | Within 5 business days |
| Initial triage / severity view | Within 10 business days of acknowledgement |
| Status update | At least every 30 days until resolved or closed |
Timelines may extend for complex multi-tenant issues. We will not publicly discuss an open report without coordinating with you, except where legally required.
After a fix (or an agreed closing decision), we may list a short acknowledgment on this page or in release notes if you opt in.
3. In scope
Only assets we operate as the IoneShop platform:
- Marketing:
ioneshop.euand country marketing hosts that redirect here (ioneshop.pl,.de,.fr,.nl,.ch) - Merchant BO:
app.ioneshop.eu - Platform admin:
admin.ioneshop.eu - Auth:
auth.ioneshop.eu - Public API / gateway hosts published for the platform (e.g.
api.ioneshop.euwhen live) - Developer portal:
developers.ioneshop.eu - Status:
status.ioneshop.cloud - Control-plane public health surfaces only (no attempts to bypass internal-only networks)
In-scope classes (examples): authentication/session flaws, broken access control, cross-tenant data exposure, SSRF against platform services, injection on platform apps, serious misconfiguration exposing platform secrets.
4. Out of scope
- Merchant storefronts and custom domains belonging to customers (including
*.shops.ioneshop.eu/*.ioneshop.business/*.shops.ioneshop.xyz/ live public demosdemo|acme.ioneshop.xyz) — report only if you can show a platform defect that enables cross-tenant impact; do not scrape or attack other merchants’ shops - Denial of service, volumetric flooding, or resource exhaustion
- Social engineering, phishing, or physical attacks against staff or customers
- Spam, content issues, or best-practice findings without security impact (e.g. missing non-security headers alone)
- Use of automated scanners that generate excessive traffic
- Findings in third-party SaaS we integrate with (report to that vendor; tell us if our config is wrong)
- Issues requiring physical access, jailbroken devices, or already-compromised admin accounts without an escalation path
5. Rules of engagement
- Act in good faith; stop testing if you encounter data that is not yours — report and delete local copies that are not needed for the PoC
- Do not modify or delete data that is not yours
- Do not pivot into customer tenants beyond the minimum needed to demonstrate a platform isolation failure
- Do not demand payment as a condition of disclosure (this is not a bounty program)
- Comply with applicable law
6. Safe harbor (good-faith research)
If you follow this policy, stay in scope, and avoid privacy harm beyond a minimal PoC, we will:
- Treat your report as authorized security research against the listed platform assets
- Not pursue legal action for that research activity itself
- Work with you in good faith if a third party questions the research
Safe harbor does not cover out-of-scope activity, extortion, public disclosure before we have a reasonable chance to remediate, or violation of law.
7. Future managed program
We may later move intake to a managed VDP platform (e.g. Intigriti, YesWeHack, or HackerOne). If we do, security.txt and this page will be updated with the canonical submission URL. Until then, email is the channel of record.
8. Related
- Platform security overview (Enterprise): /enterprise/secure
- Developer security notes: https://developers.ioneshop.eu/docs/security
- Privacy: /privacy
Related documents