This page explains how we protect data and how you can report security issues responsibly.
If you find a vulnerability, contact us privately first (please do not disclose publicly before we can respond). Include clear reproduction steps, impact, and a safe proof of concept.
In scope: this web application, this site’s public APIs, form submissions, and payments integrated on this domain.
Out of scope: DoS/DDoS, social engineering of staff, aggressive automated scanning, or issues on third-party services outside our control.
The site may store order data, contact form submissions, and admin accounts on your hosting. Order/support magic links are secrets — do not share them publicly.