Security policy
If you believe you have found a security vulnerability in Corresso, we want to hear from you. This page explains how to tell us, what we promise in return, and the rules that keep your research in safe harbour.
How to report
Email [not yet set]. Please include:
- what the vulnerability is and where — the address of the page or the request;
- the steps to reproduce it;
- what an attacker could do with it.
Write in English or Danish. The same contact is published in security.txt (RFC 9116).
What we promise
- We confirm that we have received your report, and tell you what we will do next.
- We keep you informed while we investigate and fix it, and tell you when it is fixed.
- We credit you publicly once it is fixed, if you would like us to.
- We will not take legal action against you, or ask anyone else to, for research that follows the rules below.
Safe harbour: the rules
- Test only with accounts you own or have been given for testing, and never against another customer’s data.
- If you reach anyone else’s data, stop; do not keep, copy or share it; and tell us.
- Never read, change or delete email, notes or other content that is not yours, and never send email to real people from Corresso.
- Do nothing that degrades the service for others: no denial of service, no high-volume automated scanning.
- Keep the details confidential until we have fixed the vulnerability, or until we agree on a date to publish them.
We authorise research that follows these rules. If in doubt, ask us first at [not yet set].
Out of scope
- Social engineering or phishing of our staff or customers, and physical attacks.
- Denial-of-service and volumetric attacks.
- The services of companies we use, such as Hetzner or Postmark, and your own Shopify store: report those to them.
- Reports from automated scanners without a demonstrated impact.
- Missing security headers or cookie flags that cannot be exploited.