Report Security Issues
Last Updated: September 20, 2026
If you believe you have found a security vulnerability on antonpace.shop, please contact Anton Pace promptly. We review legitimate security reports and aim to investigate and address validated issues as efficiently as possible.
Before submitting a report, please review the responsible-disclosure principles, bug-bounty guidelines, reward levels, and reporting instructions below.
Helpful Anton Pace Links
01 Responsible Disclosure Fundamentals
Anton Pace welcomes good-faith security research intended to help protect our customers and website. When reporting a security issue, please:
- Give us a reasonable amount of time to investigate and address the issue before publicly disclosing it or sharing it with others.
- Do not access, alter, or interact with private customer accounts without the account owner’s explicit permission.
- Make a good-faith effort to avoid privacy violations, service interruption, data loss, or destruction.
- Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate and document the issue.
- Comply with all applicable laws and regulations.
02 Bug Bounty Program
Anton Pace may provide discretionary rewards for qualifying researchers who identify and responsibly report valid security vulnerabilities.
Reward eligibility and amount depend on factors such as severity, practical impact, reproducibility, report quality, and whether the issue has already been reported.
03 Reward Levels
Rewards are based on the severity and practical impact of the reported vulnerability. Reports should include clear and reproducible steps. Issues that cannot be reproduced may not qualify for a bounty.
The first valid report of an issue is generally the report considered for a reward. Multiple symptoms caused by the same underlying root cause may be treated as one issue.
- Remote code execution
- Remote shell or command execution
- Vertical authentication bypass
- SQL injection exposing targeted sensitive data
- Full account takeover
- Lateral authentication bypass
- Disclosure of sensitive internal data
- Stored XSS affecting other users
- Local file inclusion
- Insecure handling of authentication cookies
- Logic or business-process flaws
- Insecure direct object references
- Open redirects
- Reflected XSS
- Low-sensitivity information disclosure
04 How to Report a Security Issue
Email security findings to:
Please include as much relevant information as possible, including:
05 Reports That May Not Qualify
Certain reports may be valid observations but may not qualify for a bounty if they do not create a meaningful security impact or require unrealistic conditions.
Contact Anton Pace
Use email for security reports whenever possible so technical details can be reviewed accurately. For general support, you may also use the contact information below.