We take the security of our customers' data seriously. If you believe you have found a vulnerability in a RevShop product, we want to hear about it, and this page tells you how to reach us and what to expect.

Reporting a vulnerability

Email security@revshop.com. Reports go straight to our engineering team.

Please include as much of the following as you can:

  • The product, URL, or API endpoint affected
  • Steps to reproduce, in enough detail that we can follow them
  • What you were able to access or do as a result
  • Any test accounts, IP addresses, or timestamps you used, so we can match your activity to our logs
  • Screenshots, a proof of concept, or a short video, if you have them

Reports in English are easiest for us to act on quickly.

Please do not report vulnerabilities through our general support channels or to individual employees. Using security@revshop.com is what gets your report in front of the right people.

What you can expect from us

  • We will acknowledge your report within 3 business days. That acknowledgement comes from a person, not an autoresponder.
  • We will give you a substantive status update within 10 business days of that acknowledgement, including our assessment of the issue, whether we have been able to reproduce it, and what we intend to do about it.
  • We will keep you informed as we work on a fix, and we will tell you when it ships.
  • We will tell you plainly if we decide not to act on a report, and why.
  • We will not ask you to sign a non-disclosure agreement as a condition of reporting.

Scope

The following are in scope:

What Where
RevShop web application application.revshop.com
RevShop API api.revshop.com
RevX app for Canva The RevShop integration published in the Canva Apps marketplace

Everything else is out of scope, including:

  • Any other revshop.com hostname, including non-production, staging, and internal environments
  • Our marketing and informational web pages
  • Third-party services we use but do not operate, including the Canva platform itself and our payment processor. Please report issues in those products to their own security teams.
  • Findings that require a compromised device, a compromised email account, or a malicious browser extension in order to work
  • Reports produced solely by an automated scanner, with no demonstrated impact

We would still rather hear about something out of scope than not hear about it. Send it, and we will tell you honestly whether we are the right people to act on it.

Rules of engagement

While you are researching, please:

  • Do not access, modify, or delete data that is not yours. If you find a way to reach another customer's data, stop at the point you have confirmed it and tell us. Do not enumerate further.
  • Do not run denial of service or load tests against our systems, and do not use scanning that degrades service for other users.
  • Do not use social engineering, phishing, or physical attacks against our staff, our customers, or our offices.
  • Use your own test accounts. If you need one and cannot register, email us and we will help.
  • Do not use a vulnerability to persist, install a backdoor, or move deeper into our infrastructure than the finding itself requires.

Safe harbour

If you follow the policy on this page and act in good faith, RevShop will not pursue legal action against you for your research, and we will not report you to law enforcement. We will treat your work as authorized activity.

If a third party brings action against you for research you conducted within this policy, we will make it known that your activity was authorized.

Good faith is the operative phrase. This safe harbour does not cover extortion, data theft, deliberate service disruption, or activity outside the rules above. If you are partway through something and unsure whether it is within the policy, stop and ask us at security@revshop.com. Asking first will never count against you.

Public disclosure

We ask that you give us 90 days from your initial report, or until a fix has shipped, whichever comes first, before publishing details of a vulnerability. If a fix is taking us longer than that, talk to us and we will agree on timing together.

This is a request, not a condition. Choosing to publish does not remove the safe harbour above.

There is no monetary reward

This is a vulnerability disclosure programme, not a bug bounty. We do not pay for reports, and we do not run a bounty platform. We want to be straightforward about that up front rather than have you find out after doing the work.

What we can offer is a real response from engineers who will read your report carefully, fix what is broken, and tell you what happened. If you would like credit, we are glad to name you when we write up the fix.

Machine-readable policy

Our security.txt file, per RFC 9116, is published at https://www.revshop.com/.well-known/security.txt.


Last updated: 5 August 2026