We take the security of our platform and our customers’ data seriously. If you believe you’ve found a vulnerability, we want to hear about it.
Reporting
Please email reports to security@guestmanager.com. PGP encryption is available on request.
What to include
A clear description of the issue, steps to reproduce, and any proof-of-concept material. The more specific the report, the faster we can act on it.
What to expect
- We aim to acknowledge reports within a few business days.
- For confirmed issues, our initial assessment usually takes a couple of weeks.
- We’ll keep you updated as we investigate and fix.
- With your permission, we’ll publicly credit you once the issue is fixed.
Scope
In scope: guestmanager.com, all *.guestmanager.com subdomains, our Shopify app GM Event Ticketing, and our public APIs.
Out of scope: third-party services we rely on (Shopify, Heroku, Stripe, etc.), social engineering, physical attacks, denial of service, and reports based solely on automated scanner output (missing security headers, SPF/DMARC alignment, version disclosure, etc.) without demonstrated impact.
Rules of engagement: Test only against accounts and data you own, or a store you create for testing. Do not access, create, modify, or delete data in other merchants’ live accounts, and do not access other people’s orders, tickets, or personal information. If a flaw can only be demonstrated using another party’s data, or by degrading the service for others, describe it in your report rather than exercising it. Research that stays within these limits is what we consider good-faith and authorized under the safe harbor below.
No paid bounty program
We do not currently offer monetary rewards. We genuinely appreciate good-faith disclosure and will credit researchers publicly with their permission.
Safe harbor
Good-faith security research conducted in accordance with this policy will not result in legal action from Guest Manager. We consider activities consistent with this policy as authorized, and will not pursue claims under the Computer Fraud and Abuse Act, similar state laws, or DMCA anti-circumvention provisions against researchers acting in good faith.