Security & Trust
How we protect your productions' data, where to find our compliance documentation, and how to report a security vulnerability.
Trust Center
Our security and compliance program in one place: SOC 2 status, security controls, policies, and subprocessors. Request access to reports and documentation for your vendor review.
Report a vulnerability
Found a security issue in Shamel Studio? Read our vulnerability disclosure guidelines below and submit a report through our vulnerability reporting form, anonymously if you prefer. No account required.
Vulnerability Disclosure Guidelines
Last updated: August 15, 2026
We value the contributions of the security research community and recognize the importance of a coordinated approach to vulnerability disclosure. If you have discovered a security vulnerability, we encourage you to let us know immediately. We welcome the opportunity to work with you to resolve the issue promptly.
Our program follows established industry norms for coordinated vulnerability disclosure, including a safe harbor for good-faith security research, described below.
Report a vulnerability
Submit your report through our reporting form. Reports go directly to our security team. You can submit anonymously, and no account is required. If you include an email address, you will receive a link to follow updates on your report.
Our reporting form is hosted on HackerOne. Prefer email? Write to security@shamelstudio.com.
What to include
To help us validate and fix the issue quickly, please include:
The affected product, URL, or endpoint (for example, app.shamelstudio.com).
A description of the vulnerability and its potential impact.
Step-by-step instructions to reproduce it, including any proof-of-concept code, requests, or screenshots.
How you would like to be credited, if at all, and how we can reach you for follow-up questions.
What to expect
We will acknowledge your report, investigate it, and keep you informed as we work toward a fix. We follow coordinated vulnerability disclosure: we ask that you give us a reasonable amount of time to remediate the issue before sharing it publicly, and we will work with you on disclosure timing once it is resolved.
Scope
In scope: app.shamelstudio.com. We also welcome reports about any other asset that is owned and operated by Shamel Inc, even if it is not listed here. If you are unsure whether an asset belongs to us, ask at security@shamelstudio.com before you begin.
Third-party systems and infrastructure operated by our service providers are not in scope and must not be tested directly. We cannot authorize research against them, and they are not bound by our safe harbor. However, vulnerabilities that result from Shamel Studio's own implementation, configuration, or integration of a third-party service may be reported through this program.
Safe testing
Please act in good faith. Do not conduct denial-of-service testing, social engineering, phishing, physical attacks, destructive testing, or any testing intended to degrade service availability. Do not intentionally access, modify, download, or delete data belonging to other users.
If you unexpectedly encounter data belonging to another user, stop testing immediately. Do not further access, download, modify, copy, or retain the data beyond the minimum evidence necessary to demonstrate the vulnerability, and report the issue to us right away.
Safe harbor
We consider security research conducted in good faith and in accordance with these guidelines to be authorized. We will not pursue or support legal action against you for such research, and we waive any restrictions in our Terms of Service that would conflict with it. If a third party brings legal action against you for good-faith research consistent with these guidelines, we will make it known that your activities were authorized. If you are unsure whether something is covered, ask us before you proceed.
A machine-readable version of this contact information is available at /.well-known/security.txt.