Security & Vulnerability Disclosure
How to report security vulnerabilities in Increlon Affiliate Marketing, and the disclosure policy, scope, safe harbor, and reward guidelines under which Intulon LLC runs its self-managed program.
This page describes how Intulon LLC operates the Increlon Affiliate Marketing application for Shopify merchants.
Reporting a vulnerability
Intulon LLC welcomes reports of security vulnerabilities in Increlon Affiliate Marketing and rewards qualifying, good-faith reports. Email security@intulon.com with enough detail to reproduce the issue.
Please include a clear description, the affected URL/endpoint or feature, step-by-step reproduction, a minimal proof of concept, and the impact you believe it has. Screenshots or a short screen recording help.
- Send reports to security@intulon.com (also published at /.well-known/security.txt).
- Report one issue per email where practical, so each can be tracked separately.
- Give us a reasonable time to investigate and remediate before any public disclosure.
Scope
The following are in scope for this program:
- The Increlon Affiliate Marketing application and its embedded admin surfaces (app.increlon.com).
- The marketing site (increlon.com) and its public pages.
- The storefront app-proxy surfaces served under a merchant's store (for example /apps/increlon-affiliate/*) and the affiliate portal.
- Our first-party API endpoints and webhooks that belong to the app.
Out of scope
The following are NOT in scope. In particular, vulnerabilities in the Shopify platform itself belong to Shopify's own program, not ours.
- The Shopify platform, Shopify Admin, checkout, or any Shopify-operated infrastructure — report those to Shopify.
- Third-party services we integrate with (for example PayPal, Wise, email providers, Bitly, Klaviyo, Mailchimp) — report those to the respective vendor.
- Denial-of-service, volumetric, or resource-exhaustion testing.
- Social engineering, phishing of our staff or merchants, and physical attacks.
- Automated scanner output without a demonstrated, exploitable impact.
- Missing best-practice headers or configuration with no concrete security impact.
Rules of engagement
- Test only against your own accounts and your own Shopify development stores — never another merchant's or affiliate's store or data.
- Do not access, modify, or destroy data that is not yours. Use the minimum interaction needed to prove an issue.
- Do not exfiltrate data, pivot, or persist access. Stop and report as soon as impact is demonstrated.
- Do not degrade, disrupt, or overload the service or the experience of merchants and their customers.
- Comply with all applicable laws and with Shopify's terms while testing.
Safe harbor
Intulon LLC will not pursue or support legal action against researchers for security research and vulnerability disclosure conducted in good faith and in accordance with this policy.
We consider such activity authorized, will work with you to understand and resolve the issue quickly, and will not treat it as a violation of our terms. If a third party initiates legal action against you for activity that complied with this policy, we will make this authorization known.
If you are unsure whether a specific test is authorized, ask us first at security@intulon.com.
Rewards
This is a self-managed program. Rewards are offered at our discretion to the first reporter of a previously-unknown, in-scope, valid vulnerability, scaled by severity (roughly CVSS) and report quality.
- Higher-severity, clearly-demonstrated issues (for example authentication bypass, cross-tenant data access, or remote code execution) receive larger rewards.
- Lower-severity issues may receive a smaller reward or public acknowledgment.
- No reward is given for duplicates, already-known issues, out-of-scope reports, theoretical findings without impact, or issues arising from a reporter violating this policy.
- Amounts, eligibility, and whether an issue qualifies are determined solely by Intulon LLC.
Our commitment
- We aim to acknowledge new reports within a few business days.
- We will keep you informed of remediation progress and tell you when the issue is resolved.
- With your permission, we are happy to credit you once a fix has shipped.