Skip to main content
No membership. No tricks. Real prices.
WEHOZ
DealsGuidesHelp

Policy

Vulnerability disclosure policy

Last updated: June 1, 2026

Wehoz takes the security of our marketplace, sellers, and shoppers seriously. We welcome reports from anyone — independent researchers, students, employees of partner companies, or accidental finders — and we will treat your report seriously regardless of the channel it arrived through.

This page is the entry point. If anything below is unclear, email security@wehoz.com and ask. We would rather answer questions than miss a report.

1. Scope

The following are in scope for this program:

  • The storefront at wehoz.com and its preview environments at dev.wehoz.com and staging.wehoz.com.
  • The Worker API at api.wehoz.com.
  • The media host at media.wehoz.com.
  • Custom software developed by Wehoz: the storefront, the seller dashboard, the admin console, and any tooling we publish under the wehoz namespace.
  • Misconfigurations in our hosted services (CDN cache poisoning, open redirects, header injection) where Wehoz controls the configuration.

2. Out of scope

The following are not covered by this policy:

  • Denial-of-service attacks, volumetric or otherwise. Do not test these.
  • Social engineering, phishing, or any attempt to obtain credentials from Wehoz employees, sellers, or shoppers.
  • Physical attacks against Wehoz offices or staff.
  • Findings on third-party services we depend on (Stripe, Shippo, Supabase, Cloudflare, Vercel, Resend, etc.) — report those to the upstream vendor under their disclosure program. We are happy to help coordinate if you need a foothold.
  • Best-practice recommendations without a demonstrated impact (e.g. "your site does not set a particular HTTP header"). These are useful and we'll often act on them, but they do not qualify as vulnerabilities under this policy.
  • Spam, abuse, or fraud (use help@wehoz.com).

3. Safe harbor

If you research in good faith under this policy, Wehoz will not pursue legal action against you, will not refer you for prosecution under the Computer Fraud and Abuse Act or the Digital Millennium Copyright Act's anti-circumvention provisions, and will not ask your internet service provider to do anything other than help us remediate.

"Good faith" means: you stayed within scope, you avoided data that does not belong to you (or accessed only the minimum needed to confirm the issue), you did not intentionally disrupt the service for other people, you did not extort us, and you gave us a reasonable opportunity to fix the issue before publishing.

If you are unsure whether a piece of research would be in scope or in good faith, email us before you start. We will say yes or no in writing within 48 hours.

4. How to report

Send your report to security@wehoz.com. Include:

  • A description of the issue.
  • The exact URL, request, or sequence of steps to reproduce.
  • What you believe the impact is — what an attacker could do with the issue.
  • Any proof-of-concept output. Redact data you accessed by accident.

If you want to encrypt your report, our PGP key is published at the bottom of this page and is also linked from /.well-known/security.txt.

5. What you can expect from us

  • Acknowledgement within 48 hours of receipt, business days or not.
  • A triage decision within 7 days — confirmed, won't fix with rationale, or out of scope.
  • Resolution targets: 30 days for high-severity, 60 days for medium, 90 days for low.
  • An invitation to coordinate disclosure. Our default is a 90-day window from triage to public disclosure, which can be shortened or extended by mutual agreement.
  • If you are the first to report a qualifying issue, attribution on our acknowledgements list with your preferred name or handle. Anonymous reporters are also welcome.

6. What we ask of you

  • Stop testing as soon as you have a working proof. Do not pivot from one issue into another without checking in.
  • Do not download, exfiltrate, or retain customer data, seller data, or any data not your own.
  • Do not change or delete data that is not yours.
  • Wait for our written confirmation before publishing any details of the issue.
  • If you accidentally accessed data that does not belong to you, tell us and delete it.

7. Coordinated disclosure

We prefer coordinated disclosure. Once an issue is fixed and rolled out, we will work with you on the timing of any public write-up. If you want to publish on a specific date — a conference talk, a research deadline — let us know early and we'll do our best to accommodate. If we cannot fix in 90 days, we will tell you why and propose a revised date rather than ask for indefinite silence.

8. Bug bounty

Wehoz does not currently run a paid bug bounty. We are a small team and we want to set expectations honestly. We do thank researchers publicly with their permission (see below), and we are happy to send Wehoz merchandise to people whose reports led to real fixes. As the company grows, this section will change.

9. Researcher acknowledgements

We are grateful to everyone who has reported a security issue to us. The list will appear here as we receive and resolve reports. If you would like to be listed, mention that in your report; if you would prefer to stay anonymous, we will honor that.

No reports have been acknowledged yet — this list will update as we receive valid disclosures.

PGP key

We can accept encrypted reports. To get our current PGP key, email security@wehoz.com with the subject "PGP key request" and we will send the key fingerprint plus the public key over a separate channel for verification. We rotate the key annually and after any suspected compromise.

Changes to this policy

We will update this page when our scope, contact, or process changes. The version control history is in our codebase and we will note the "last updated" date at the top. If a change materially affects researchers in progress, we will email everyone we have heard from in the past year.

  • Home & Kitchen
  • Pet
  • Personal Care
  • Outdoor
  • Office
  • Beauty
  • Deals
  • Buying Guides
  • Picks Under $50
  • Kitchen Under $100
  • Best Sellers
  • New Arrivals
  • On Sale
  • Fragrance-Free Skincare
  • Linen Bedding
  • Coffee Makers
  • Browse all shop pages
  • Help Center
  • Track Order
  • Contact Support
  • Shipping
  • Returns
  • About Wehoz
  • No Membership
  • Team
  • Careers
  • Sell on Wehoz
  • Seller Help
  • Wehoz for Brands
  • Refer a friend
  • Affiliate program
  • Terms
  • Privacy
  • Returns
  • Buyer Protection
  • Cookies
  • Accessibility
  • CCPA / Do Not Sell
  • DMCA
  • All policies

Get Updates

No membership offer. We only email about orders and product news.

  • Visa
  • MC
  • Amex
  • Discover
  • Apple Pay
  • Google Pay
  • Link
  • Affirm
  • Klarna

© 2026 WEHOZ INC

No membership. No tricks. Real prices. Ever.