ShipMsg
Legal centerSecurityContact legal

Legal

Security and Vulnerability Disclosure

ShipMsg security controls and the rules for reporting a suspected vulnerability safely.

Effective September 3, 2026

Security program

ShipMsg uses tenant and environment isolation, least-privilege workload identities, encryption in transit and for protected data at rest, credential sealing, signed webhooks, malware scanning, append-only audit evidence, monitored queues and controllers, dependency review, immutable releases, backups and tested restoration. Controls are risk-based and evolve with the service. No system can guarantee absolute security.

Report a vulnerability

Email security@shipmsg.comwith the affected URL or component, reproduction steps, impact, relevant timestamps and a safe contact method. Do not include live customer data, credentials or destructive payloads. ShipMsg will acknowledge a credible report, investigate, communicate status at reasonable intervals and coordinate remediation and disclosure where appropriate.

Authorized good-faith research

We will not pursue legal action solely for good-faith research that avoids privacy harm, service disruption and unlawful access; uses only accounts and data you own or have written permission to test; stops when sensitive data is encountered; reports promptly; preserves confidentiality while we remediate; and complies with applicable law. This is not authorization to test Meta, Cloudflare, Oracle, Stripe, Twilio or any other third party.

Out of scope

  • Denial of service, load testing, spam, social engineering or physical attacks.
  • Accessing, modifying, deleting or exfiltrating another customer's data.
  • Automated scans that impair service or ignore rate limits.
  • Extortion, public disclosure before remediation, or demands for payment.
  • Provider issues that do not result from ShipMsg code or configuration.

Customer responsibilities

Customers must protect credentials, enable available MFA, restrict roles, review users and integrations, rotate exposed secrets, validate webhook signatures, maintain secure recipient systems, and notify ShipMsg promptly of suspected compromise. Security summaries may be requested under appropriate confidentiality terms.

Contact

ShipMsg legal questions: legal@shipmsg.com. Privacy questions and rights requests: privacy@shipmsg.com. ShipMsg support questions: support@shipmsg.com. Do not email passwords, payment-card data, message content, or identity documents; ShipMsg will provide a secure verification channel when needed.

© 2026 ShipMsg.All legal documents