Vulnerability Disclosure
Our Commitment to Security
ChefStead values the trust our customers place in us.
We work to protect our website, customer information, and digital services through responsible security practices. We also recognize that security vulnerabilities can exist despite reasonable efforts to prevent them.
This Vulnerability Disclosure Policy provides guidance for security researchers and members of the public who identify a potential vulnerability in a ChefStead-owned digital system.
We welcome good-faith reports that help us identify and resolve legitimate security issues.
Scope
This policy applies only to publicly accessible digital assets that are owned and directly controlled by ChefStead, including:
-
https://chefstead.com -
https://www.chefstead.com -
ChefStead-owned subdomains specifically identified as in scope
-
Other ChefStead-owned systems that expressly link to this policy
If you are uncertain whether a system is owned or controlled by ChefStead, please contact us before beginning any testing.
Third-Party Services
ChefStead may use third-party platforms and service providers for ecommerce, payments, hosting, analytics, customer reviews, email, shipping, customer support, and other functions.
Third-party systems are not authorized for testing under this policy, even when they are linked to, embedded in, or accessible through a ChefStead website.
Out-of-scope third-party services may include:
-
Shopify and Shopify-managed infrastructure
-
Payment processors and financial institutions
-
Shipping and logistics providers
-
Customer review platforms
-
Email and messaging providers
-
Analytics and advertising services
-
Content delivery and security networks
-
Customer support applications
-
Social media accounts and platforms
-
Other vendor-operated systems
If you believe a third-party system contains a vulnerability, report it directly to that provider under its applicable disclosure policy.
If the issue appears to result from a configuration or integration controlled by ChefStead, you may report the issue to us, but you must not continue testing the third-party service without the provider’s authorization.
Authorized Security Research
Security research is considered to be conducted in good faith under this policy when you:
-
Test only systems expressly identified as in scope
-
Use only accounts and data that belong to you or that you have explicit permission to use
-
Limit testing to what is reasonably necessary to confirm the existence of a vulnerability
-
Avoid accessing, copying, modifying, downloading, or deleting another person’s data
-
Stop testing immediately if you encounter personal, confidential, financial, or proprietary information
-
Avoid disrupting the availability or performance of any system
-
Report the vulnerability promptly and privately
-
Provide us with a reasonable opportunity to investigate and remediate the issue
-
Comply with applicable law and this policy
This policy does not authorize access to systems, accounts, networks, or data owned or controlled by third parties.
Prohibited Activities
The following activities are not authorized:
-
Denial-of-service or distributed denial-of-service testing
-
High-volume automated scanning that may impair service
-
Destructive testing
-
Malware deployment
-
Ransomware, extortion, or threats
-
Social engineering, phishing, or impersonation
-
Physical attacks against facilities, equipment, or personnel
-
Testing of employees, suppliers, contractors, or customer accounts
-
Credential stuffing or use of credentials obtained from data breaches
-
Brute-force attacks or password spraying
-
Accessing, downloading, changing, or deleting customer information
-
Creating, modifying, or canceling another customer’s order
-
Initiating fraudulent purchases, refunds, chargebacks, or shipments
-
Testing payment card information or financial systems
-
Bypassing rate limits in a manner that degrades service
-
Persistence, lateral movement, or pivoting into additional systems
-
Exfiltration of data
-
Public disclosure before coordinated remediation
-
Any activity that violates applicable law or the rights of another person
If you accidentally access sensitive information, stop testing immediately, do not retain or share the information, and notify us in your report.
Vulnerabilities We Encourage You to Report
Examples of potentially eligible security issues include:
-
Authentication or authorization failures
-
Unauthorized access to customer or administrative data
-
Cross-site scripting
-
Cross-site request forgery with a meaningful security impact
-
SQL injection or other injection vulnerabilities
-
Server-side request forgery
-
Remote code execution
-
Insecure direct object references
-
Privilege escalation
-
Exposure of valid credentials, API keys, or private tokens
-
Significant security misconfigurations
-
Vulnerabilities that could affect the confidentiality, integrity, or availability of ChefStead-controlled systems
A report should describe a specific, reproducible security impact.
Generally Ineligible Reports
The following findings generally do not qualify unless they create a demonstrated and meaningful security risk:
-
Missing security headers without an exploitable impact
-
Informational TLS or SSL configuration observations
-
Self-cross-site scripting
-
Clickjacking on pages without sensitive actions
-
Username or email enumeration without additional impact
-
Missing cookie attributes on non-sensitive cookies
-
Public information intentionally displayed on the website
-
Version disclosure or software fingerprinting
-
Best-practice recommendations without a specific vulnerability
-
Issues requiring physical access to a user’s device
-
Issues affecting unsupported or obsolete browsers
-
Vulnerabilities that depend entirely on social engineering
-
Reports generated only by automated tools without manual validation
-
Previously reported or already known issues
-
Vulnerabilities exclusively affecting an out-of-scope third-party service
-
Spam, content complaints, or general customer service matters
ChefStead will determine whether a report presents a valid security issue based on its actual impact and reproducibility.
How to Report a Vulnerability
Please send vulnerability reports to:
Security email: support@chefstead.com
Use the subject line:
Security Vulnerability Report – [Brief Description]
Please include:
-
The affected domain, page, endpoint, or feature
-
A clear description of the vulnerability
-
The date and time the issue was observed
-
Detailed reproduction steps
-
The potential security impact
-
Screenshots, logs, or a limited proof of concept
-
The browser, device, operating system, or tools used
-
Whether any customer or confidential information was encountered
-
Your name or preferred researcher attribution, if desired
-
A secure method for contacting you
Please do not include unnecessary personal information, full customer records, payment information, passwords, private keys, or large data extracts in your initial report.
If sensitive information must be shared to explain the issue, contact us first so that we can arrange an appropriate secure method.
What You Can Expect From Us
For reports submitted in accordance with this policy, ChefStead will aim to:
-
Acknowledge receipt within five business days
-
Conduct an initial review within ten business days
-
Request additional information when necessary
-
Keep you reasonably informed about material progress
-
Work in good faith to validate and address confirmed vulnerabilities
-
Notify you when the issue has been resolved or otherwise closed
-
Provide appropriate credit if requested and mutually agreed upon
Resolution time will depend on the severity and complexity of the issue, the affected system, and whether remediation requires coordination with a third-party provider.
These timeframes are targets and not guarantees.
Coordinated Disclosure
Please keep all vulnerability information confidential until ChefStead has confirmed that the issue has been resolved or has provided written permission for disclosure.
We ask researchers to allow a reasonable remediation period before publishing or sharing information about a vulnerability. The appropriate period may vary depending on severity, complexity, customer risk, and necessary third-party coordination.
Public disclosure should not include:
-
Personal or customer information
-
Credentials or private security keys
-
Information that would enable continuing exploitation
-
Confidential business information
-
Details relating to an unresolved third-party vulnerability
ChefStead will make reasonable efforts to coordinate with researchers regarding any proposed public disclosure.
Safe Harbor
When you conduct security research in good faith and in accordance with this policy, ChefStead will consider your activities authorized with respect to ChefStead-owned systems covered by this policy.
ChefStead will not initiate or recommend legal action against you for accidental, good-faith violations of this policy when you:
-
Avoid harm to ChefStead, its customers, and third parties;
-
Stop testing and report the issue promptly;
-
Do not misuse, retain, or disclose accessed information; and
-
Cooperate with reasonable efforts to investigate and remediate the issue.
If a third party initiates legal action concerning research conducted under this policy, ChefStead may, at its discretion, clarify that the activity was conducted in accordance with our policy.
This safe harbor:
-
Applies only to legal rights that ChefStead has authority to waive;
-
Does not bind law enforcement, regulators, or third parties;
-
Does not authorize violations of applicable law; and
-
Does not apply to extortion, threats, intentional harm, privacy violations, or activity outside the defined scope.
If you are uncertain whether a proposed action is permitted, contact us before proceeding.
Customer and Personal Data
Protecting customer privacy is essential.
If you encounter personal or confidential information:
-
Stop testing immediately.
-
Do not view more information than necessary to recognize the exposure.
-
Do not download, copy, modify, retain, or share the information.
-
Describe the type of information encountered without including the information itself.
-
Notify ChefStead promptly.
-
Securely delete any data unintentionally retained after receiving confirmation that it is no longer needed.
Accessing customer data beyond the minimum necessary to demonstrate a vulnerability is not authorized.
Recognition and Compensation
ChefStead appreciates responsible security research, but this policy is not a bug bounty program.
We do not promise financial compensation, gifts, products, or other rewards for vulnerability reports. Any recognition or reward is entirely at ChefStead’s discretion and must be agreed to in writing.
Researchers may not demand payment or threaten disclosure, disruption, or data release in exchange for compensation.
Policy Updates
ChefStead may update this policy as our website, technology providers, security practices, and legal obligations evolve.
Researchers should review the current version of this policy before beginning any testing.