Vulnerability Disclosure Policy
Last Updated: August 7th, 2026
1. Introduction
At SolSnazycat, we take the security of our website and the privacy of our customers seriously. We appreciate the efforts of security researchers and independent white-hat hackers in helping us identify and remediate security vulnerabilities.
This Vulnerability Disclosure Policy outlines our process for receiving and handling vulnerability reports. By following this policy, you help us maintain a secure environment for our users.
2. Scope
This policy applies to the following assets:
- Domain:
solsnazycat.ca(includingwww.solsnazycat.ca) - Infrastructure: Our web servers, APIs, and associated cloud services hosted on InfinityFree and Cloudflare.
Out of Scope:
- Third-party services we link to (e.g., Stripe, PayPal, CJ Dropshipping).
- Social engineering attacks against our employees.
- Denial of Service (DoS/DDoS) attacks.
- Vulnerabilities related to software versions that are no longer supported by the vendor.
3. Our Commitment (Safe Harbor)
We consider vulnerability research a critical part of our security posture. Therefore:
- No Legal Action: If you follow this policy, we will not pursue legal action against you for good-faith vulnerability research.
- Good Faith: You must act in good faith, meaning you do not exploit the vulnerability for personal gain, damage our systems, or access other users’ data.
- Privacy: You must not access or modify other users’ data. If you inadvertently access data, stop immediately and report it.
4. Reporting Guidelines
If you discover a potential security vulnerability, please report it immediately to our security team.
- Email:
solsnazycatcs@solsnazycat.ca - Subject Line: Please use the format:
[Vulnerability Report] - [Brief Description](e.g.,[Vulnerability Report] - XSS in Contact Form)
Include the following in your report:
- Description: A clear description of the vulnerability.
- Steps to Reproduce: Detailed steps to reproduce the issue.
- Proof of Concept (PoC): Screenshots, videos, or code snippets (if applicable).
- Impact: A description of the potential impact if the vulnerability were exploited.
- Contact Info: Your name and preferred method of contact (optional, but helpful for coordination).
5. Response Timeline
We strive to acknowledge all reports within 48 hours.
- Initial Acknowledgment: We will confirm receipt of your report.
- Status Update: We will provide an update on the investigation within 7 days.
- Resolution: We aim to resolve critical vulnerabilities within 30 days, depending on complexity.
6. Disclosure
- Coordination: We will coordinate with you before publicly disclosing any vulnerability.
- Credit: If you wish to be credited for your discovery, please let us know. We will acknowledge your contribution in our security changelog or press release (if applicable).
- Embargo: Please do not publicly disclose the vulnerability until we have confirmed it is fixed.
7. What We Do Not Accept
We will not accept reports for:
- Vulnerabilities in third-party software where we have no control (e.g., WordPress core, unless it’s a specific configuration issue).
- Social engineering or physical security attacks.
- Spam or phishing campaigns.
- Attacks that require user interaction (e.g., clicking a link) unless it is a critical security flaw.
8. Contact Us
If you have any questions about this policy, please contact us at:
- Email:
solsnazycatcs@solsnazycat.ca - Address: 208-3501 Centennial Dr, Vernon, B.C. V1T 2T8, Canada