Anton Pace

Report Security Issues

Last Updated: September 20, 2026

If you believe you have found a security vulnerability on antonpace.shop, please contact Anton Pace promptly. We review legitimate security reports and aim to investigate and address validated issues as efficiently as possible.

Before submitting a report, please review the responsible-disclosure principles, bug-bounty guidelines, reward levels, and reporting instructions below.

SECURITY & PRIVACY

Helpful Anton Pace Links

01 Responsible Disclosure Fundamentals

Anton Pace welcomes good-faith security research intended to help protect our customers and website. When reporting a security issue, please:

  • Give us a reasonable amount of time to investigate and address the issue before publicly disclosing it or sharing it with others.
  • Do not access, alter, or interact with private customer accounts without the account owner’s explicit permission.
  • Make a good-faith effort to avoid privacy violations, service interruption, data loss, or destruction.
  • Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate and document the issue.
  • Comply with all applicable laws and regulations.
Anton Pace’s intent is to support responsible, good-faith security research. Researchers who follow these guidelines and applicable law should clearly document their actions in the report.

02 Bug Bounty Program

Anton Pace may provide discretionary rewards for qualifying researchers who identify and responsibly report valid security vulnerabilities.

Reward eligibility and amount depend on factors such as severity, practical impact, reproducibility, report quality, and whether the issue has already been reported.

Follow the Guidelines Comply with the responsible-disclosure principles above.
Report a Real Security Risk The issue must present a meaningful privacy or security risk.
Use the Security Contact Submit reports through the designated Anton Pace security email.
Disclose Accidental Impact Tell us about any accidental privacy or service impact caused during testing.
Allow Time for Review Valid reports are reviewed based on risk and may require investigation time.
Publication Rights Anton Pace may publish or summarize submitted reports where appropriate.

03 Reward Levels

Rewards are based on the severity and practical impact of the reported vulnerability. Reports should include clear and reproducible steps. Issues that cannot be reproduced may not qualify for a bounty.

The first valid report of an issue is generally the report considered for a reward. Multiple symptoms caused by the same underlying root cause may be treated as one issue.

Critical Severity $200
  • Remote code execution
  • Remote shell or command execution
  • Vertical authentication bypass
  • SQL injection exposing targeted sensitive data
  • Full account takeover
High Severity $100
  • Lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored XSS affecting other users
  • Local file inclusion
  • Insecure handling of authentication cookies
Medium Severity $50
  • Logic or business-process flaws
  • Insecure direct object references
Low Severity Recognition Only
  • Open redirects
  • Reflected XSS
  • Low-sensitivity information disclosure
Rewards are discretionary and may be adjusted or declined based on scope, impact, duplicate status, exploitability, report quality, or other relevant factors.

04 How to Report a Security Issue

Email security findings to:

contact@antonpace.shop Suggested subject: Security Report

Please include as much relevant information as possible, including:

Reproduction Steps Clear, step-by-step instructions that allow us to reproduce the issue.
Affected Endpoint URL, page, function, API endpoint, or component affected.
Impact A concise explanation of the practical security or privacy risk.
Proof of Concept Relevant screenshots, requests, payloads, or other material needed to validate the issue.
Testing Details Describe any accounts, systems, or test conditions used.
Accidental Impact Disclose any unintended access, data exposure, or service disruption that occurred.

05 Reports That May Not Qualify

Certain reports may be valid observations but may not qualify for a bounty if they do not create a meaningful security impact or require unrealistic conditions.

Duplicate Reports Issues previously reported or already known to Anton Pace.
Non-Reproducible Reports Issues that cannot be independently reproduced from the submitted information.
Purely Informational Findings Observations without a demonstrated security or privacy impact.
Social Engineering Attempts involving phishing, impersonation, or manipulation of customers or staff.
Denial-of-Service Testing Testing that intentionally disrupts or degrades website availability.
Physical Security Testing Testing of offices, facilities, staff, or physical infrastructure is outside scope.
SECURITY CONTACT

Contact Anton Pace

Use email for security reports whenever possible so technical details can be reviewed accurately. For general support, you may also use the contact information below.