ReferralCandy
  • Referrals
  • Affiliates
  • Loyalty
  • Pricing
  • Launch your program

    Rewards & commissions↗Fraud protection↗Customer experience↗Explore all features →

    Manage and measure

    Automation & payouts↗Tracking & analytics↗Campaigns & segmentation↗

    Integrations

    ShopifyWooCommerceKlaviyoRechargeOmnisend
    Explore integrations →API & developer docs ↗
  • Learn and grow

    BlogIdeas and advice for growing through word of mouth.Referral marketing guidePlan a program your customers want to share.Affiliate marketing guideFind partners and build your commission strategy.

    Plan and launch

    Customer storiesExplore the offers and results behind real programs.ROI calculatorWork through the potential economics of your program.Help centerSetup, migration, and answers to product questions.
    Branch Basics cleaning products
    Customer storyBranch Basics

    $1.5M+ in referral revenue

    See customer results ↗
    Product updates ↗Partners ↗
  • Log in
Log inStart free trial →

Vulnerability Reporting Program

Effective: October 7, 2026
On this page
  • Applications in Scope
  • Eligibility and Responsible Disclosure
  • Timelines for Reporting and Resolution
  • Out-of-Scope Vulnerabilities
  • How to Report Vulnerabilities to Us
On this page
  • Applications in Scope
  • Eligibility and Responsible Disclosure
  • Timelines for Reporting and Resolution
  • Out-of-Scope Vulnerabilities
  • How to Report Vulnerabilities to Us

Applications in Scope

We are interested in identifying and addressing critical vulnerabilities in our infrastructure. Specifically, we focus on issues that could substantially impact the confidentiality, integrity, or availability of user data.

While we welcome all reports, not every finding will qualify for a reward. The decision to offer a reward will be at the discretion of the security team, based on the severity and impact of the reported vulnerability.

Important:

  • Avoid Denial-of-Service (DoS) attacks, spam, or any activity that could disrupt our systems or degrade service availability.
  • Refrain from using tools that generate excessive traffic during testing.

Eligibility and Responsible Disclosure

To ensure the security and privacy of our users, please adhere to the following guidelines:

  1. Report the Vulnerability: Share the technical details with us, including the exact domain and steps to reproduce the issue.
  2. Avoid Automated Scanning Tools: Do not spam our applications with automated vulnerability scanners.
  3. Do Not Make Public Disclosures: Give us adequate time to respond and address the issue before discussing it publicly.
  4. Do Not Modify User Data: You must not alter, save, transfer, or interact with data that does not belong to you.
  5. Respect Privacy: Avoid violating privacy rights, destroying data, or disrupting our services.
  6. Follow Legal and Ethical Guidelines: Testing must comply with applicable laws and must not intentionally disrupt other users or systems.

Timelines for Reporting and Resolution

We classify each verified vulnerability by severity, using CVSS v3.1 and our own assessment of its business impact:

SeverityCVSS scoreExample impact
Critical9.0–10.0Remote code execution, privilege escalation, unauthenticated data exfiltration
High7.0–8.9Authentication bypass, injection vulnerabilities, exposure of sensitive data
Medium4.0–6.9Information disclosure, privilege abuse, limited exploitability
LowBelow 4.0Minor misconfigurations or informational findings

The severity sets how quickly we respond:

SeverityAcknowledgmentContainment / MitigationFull RemediationVerification & Closure
CriticalWithin 1 business dayWithin 1 business dayWithin 3 daysWithin 7 days
HighWithin 2 business daysWithin 3 business daysWithin 7 daysWithin 10 days
MediumWithin 5 business daysWithin 10 business daysWithin 30 daysWithin 45 days
LowWithin 10 business daysAs scheduledWithin 90 daysWithin 120 days

We will confirm receipt of your report within the acknowledgment time for its severity, and may request additional details if necessary. The other times count from that acknowledgment. If a full fix cannot be completed in time, we apply a temporary mitigation until it is.

Once the issue is resolved:

  • Reward Decision:
    • Timeline: Within 15 business days after resolution.
    • If applicable, we will inform you of your eligibility for a reward. Reward decisions are based on the severity and impact of the vulnerability.
  • Public Disclosure (Optional):
    • Timeline: After mutual agreement or post-resolution (at least 90 days).
    • Public disclosure can only occur after we provide explicit approval and after the issue is resolved.

Out-of-Scope Vulnerabilities

The following reports are out of scope:

  • Weak password policies or lack of email/account verification.
  • Reports from automated tools without clear analysis.
  • Spam-related vulnerabilities or excessive email rates.
  • Issues affecting outdated browsers or platforms no longer supported by their vendors.
  • Well known exploits

How to Report Vulnerabilities to Us

When reporting a vulnerability:

  1. Include the exact domain and detailed reproduction steps.
  2. Clearly outline the potential impact of the vulnerability.

Contact Email: security@anafore.com

Our security team is committed to maintaining open communication and resolving issues promptly. Thank you for helping us improve the safety and reliability of our systems.

ReferralCandy

Genuine relationships grow brands. Referral and affiliate programs for Shopify brands with something worth recommending.

Product

ReferralsAffiliatesLoyaltyIntegrationsPricingProduct Updates

Resources

BlogROI calculatorCase studiesHelp centerReferral marketing strategyReferral program examplesAffiliate marketing guide

Company

AboutContactPartnersAgencies
© 2026 ReferralCandy. Made for merchants with something worth recommending.
Privacy · Terms