Security
Reporting a security issue
If you think you have found a vulnerability in Skuvelo, write to us. We would rather hear from you early and informally than not at all.
Last updated August 11, 2026
Where to write
security@skuvelo.com — monitored. Include the affected URL or endpoint, what you did, and what happened. A short description is fine.
What we commit to
These are promises, not aspirations. If we fail one of them, say so in a reply and we will fix it.
- We will acknowledge your report.
- We will tell you what we found — not the least we can get away with.
- We will tell you when it is fixed.
- We will not pursue or support legal action against anyone who reports a vulnerability in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix the issue before disclosing it publicly.
We do not run a paid bug-bounty programme, and we do not promise a response deadline we have not yet earned the right to promise. What we do promise is a reply from a person.
What we ask of you
One of these matters more than the rest: the data in Skuvelo belongs to merchants and to their customers, not to us.
- Do not access, modify, or retain data belonging to a Skuvelo customer or their end customers. If a proof of concept would require customer data, describe it rather than collecting it.
- Do not run automated scanning against production.
- Do not degrade service for merchants who are running their business on it.
- Give us reasonable time to fix an issue before publishing it.
Scope
skuvelo.com and its subdomains, and the Skuvelo application and API.
A report about a third-party service Skuvelo connects to should go to that service's own security contact. Tell us as well if it affects Skuvelo customers — we would rather hear it twice than not at all.
d/b/a Skuvelo