1. Reporting
If you believe you've found a security vulnerability affecting Zebra House Co., email security@zebrahouseco.com with a description of the issue, the steps to reproduce it, and its potential impact. Please don't file a public issue or post about it before we've had a chance to respond.
2. Scope
In scope:
- zebrahouseco.com and its subdomains
- Authentication, authorization, and account-isolation issues
- Data exposure — seeing another member's private data, orders, or account details
- Injection, XSS, CSRF, and similar application-layer vulnerabilities
Out of scope:
- Vulnerabilities in third-party services we build on (Stripe, Printful, Supabase, Resend, Google) — please report those directly to the provider
- Denial-of-service, spam, or automated volumetric testing against production
- Social engineering, phishing, or physical attacks against staff or members
- Reports generated purely by automated scanners without a demonstrated impact
3. Ground rules
Only test against accounts you control. Don't access, modify, or exfiltrate another member's data — stop and report as soon as you've confirmed an issue exists. Give us a reasonable window to investigate and fix a report before disclosing it publicly.
4. What to expect
We aim to acknowledge reports within a few business days. Zebra House Co. is a small, independent team, so timelines on a fix will vary with severity — we'll keep you updated as we work through it. A good-faith report that follows this policy will not result in legal action from us.
