Responsible disclosure
Security Policy
Last updated: July 12, 2026
Case Finds (casefinds.com) takes the security of our website and customers seriously. If you believe you have found a security vulnerability, we appreciate responsible disclosure and will work with you to understand and address valid reports.
At a glance
- Scope
- casefinds.com and official Case Finds web properties linked from this domain (store pages, checkout, newsletter signup API).
- Report to
- [email protected] with subject line Security report.
- Response
- We aim to acknowledge reports within 5 business days.
- Safe harbor
- Good-faith research that follows this policy will not be pursued as unauthorized access, provided you do not harm users or our service.
What to report
Please report issues such as:
- Cross-site scripting (XSS), SQL injection, or similar web vulnerabilities
- Authentication, session, or access-control flaws on our site
- Server misconfiguration that exposes sensitive data
- Issues in our newsletter signup or other Case Finds APIs that affect confidentiality or integrity
Out of scope
The following are not in scope for this policy:
- Denial-of-service (DoS/DDoS) or load-testing against production
- Social engineering, phishing, or physical attacks
- Reports about third-party services (payment processors, Cloudflare, AWS, email providers)
- Missing security headers or best-practice hardening with no demonstrated exploit
- Copyright or trademark concerns about phone case designs — use our form or email [email protected] instead
- Customer order, refund, or general support issues — email [email protected]
Rules of engagement
- Do not access, modify, or delete data that is not yours.
- Do not interact with real customer accounts without explicit written permission from us.
- Use minimal testing needed to demonstrate the issue; stop once you have confirmed the vulnerability.
- Do not publicly disclose the issue until we have had a reasonable time to fix it (typically 90 days).
- Do not scrape personal data from our systems.
How to submit a report
Email [email protected] and include:
- A clear description of the vulnerability and its impact
- Steps to reproduce (URLs, requests, screenshots, or proof-of-concept if available)
- Your name or handle and a way to reach you for follow-up
We may ask for additional information. If you prefer encrypted communication, say so in your message and we will provide a suitable channel if available.
Recognition & rewards
We do not currently operate a paid bug bounty program. We are grateful for good-faith reports and may acknowledge researchers with permission after an issue is resolved.
security.txt
Machine-readable contact details for security researchers may also be published at /.well-known/security.txt.