Responsible disclosure

Security Policy

Last updated: July 12, 2026

Case Finds (casefinds.com) takes the security of our website and customers seriously. If you believe you have found a security vulnerability, we appreciate responsible disclosure and will work with you to understand and address valid reports.

At a glance

Scope
casefinds.com and official Case Finds web properties linked from this domain (store pages, checkout, newsletter signup API).
Report to
[email protected] with subject line Security report.
Response
We aim to acknowledge reports within 5 business days.
Safe harbor
Good-faith research that follows this policy will not be pursued as unauthorized access, provided you do not harm users or our service.

What to report

Please report issues such as:

  • Cross-site scripting (XSS), SQL injection, or similar web vulnerabilities
  • Authentication, session, or access-control flaws on our site
  • Server misconfiguration that exposes sensitive data
  • Issues in our newsletter signup or other Case Finds APIs that affect confidentiality or integrity

Out of scope

The following are not in scope for this policy:

  • Denial-of-service (DoS/DDoS) or load-testing against production
  • Social engineering, phishing, or physical attacks
  • Reports about third-party services (payment processors, Cloudflare, AWS, email providers)
  • Missing security headers or best-practice hardening with no demonstrated exploit
  • Copyright or trademark concerns about phone case designs — use our form or email [email protected] instead
  • Customer order, refund, or general support issues — email [email protected]

Rules of engagement

  • Do not access, modify, or delete data that is not yours.
  • Do not interact with real customer accounts without explicit written permission from us.
  • Use minimal testing needed to demonstrate the issue; stop once you have confirmed the vulnerability.
  • Do not publicly disclose the issue until we have had a reasonable time to fix it (typically 90 days).
  • Do not scrape personal data from our systems.

How to submit a report

Email [email protected] and include:

  • A clear description of the vulnerability and its impact
  • Steps to reproduce (URLs, requests, screenshots, or proof-of-concept if available)
  • Your name or handle and a way to reach you for follow-up

We may ask for additional information. If you prefer encrypted communication, say so in your message and we will provide a suitable channel if available.

Recognition & rewards

We do not currently operate a paid bug bounty program. We are grateful for good-faith reports and may acknowledge researchers with permission after an issue is resolved.

security.txt

Machine-readable contact details for security researchers may also be published at /.well-known/security.txt.