Report a Security Issue
Effective date: August 17, 2026
We take the security of our site and our customers seriously, and welcome reports from security researchers acting in good faith.
Scope
This policy covers ironpeck.com and our checkout systems. Social engineering, physical attacks, and denial-of-service testing are out of scope.
How to Report
Email contact@ironpeck.com with a clear description of the issue, the steps to reproduce it, and any relevant screenshots or logs.
What to Expect
We aim to acknowledge reports within 2 business days and keep you updated as we investigate and resolve the issue.
Responsible Disclosure
Please give us a reasonable amount of time to address a reported issue before disclosing it publicly. We will not pursue legal action against researchers who report issues in good faith and follow this policy.
Recognition
We do not currently offer a paid bug bounty, but we are happy to publicly credit researchers who would like acknowledgment.