# Security Policy We take the security of Shipfox seriously and appreciate the efforts of security researchers and users who report vulnerabilities to us responsibly. ## Reporting a vulnerability **Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.** Instead, email us at **security@shipfox.io**. If you would like to encrypt your report, ask us for a public key in your first message. Please include as much of the following as you can, to help us triage the issue quickly: - The type of issue (for example: authentication bypass, token leakage, injection, privilege escalation). - The affected component, package, or endpoint, and the version, branch, or commit. - Step-by-step instructions to reproduce the issue. - Proof-of-concept or exploit code, if available. - The impact of the issue, including how an attacker might exploit it. ## What to expect - We will acknowledge your report within **3 business days**. - We will keep you informed as we investigate and work on a fix. - We will let you know when the issue is resolved, and we are happy to credit you in the disclosure unless you prefer to remain anonymous. Please give us a reasonable amount of time to address the issue before any public disclosure. ## Scope Reports about the code in this repository and the Shipfox service are in scope. When in doubt, email us and we will help you determine whether an issue is in scope. Thank you for helping keep Shipfox and its users safe.