Skip to content

Security & Vulnerability Disclosure

How to report a security vulnerability in Bird, what we commit to in return, and the terms under which we authorise security research against our systems.

Reporting a vulnerability

Send reports to security@birdchime.com, including:

  • The affected URL, endpoint, or app surface, and steps to reproduce
  • The impact: what an attacker gains, and under what preconditions
  • Supporting evidence, such as a proof of concept or a screen capture
  • The test store domain you used, so we can correlate against our logs

We accept reports at any severity, and require neither a minimum CVSS score nor a working exploit.

Our response process

We acknowledge within 3 business days, and within 10 business days we verify the report, classify it using CVSS v3.1, and tell you the outcome. If we do not consider it a vulnerability, we explain why. We remediate against these targets and tell you when the fix is live.

SeverityScoreTarget
CriticalCVSS 9.0 to 10.072 hours
HighCVSS 7.0 to 8.97 days
MediumCVSS 4.0 to 6.930 days
LowCVSS 0.1 to 3.990 days

Targets run from the point we verify the report, and mean a fix or a mitigation that removes the exposure. We ask for a reasonable window to remediate before you disclose publicly, and will not ask you to withhold disclosure indefinitely.

Scope

In scope:

  • The Bird Pickup & Delivery Shopify app, its API, and its extensions
  • birdchime.com and help.birdchime.com

Out of scope:

  • Merchant storefronts. These belong to our customers, not to us. A store running Bird is not authorisation to test that store.
  • The Shopify platform itself. Report those through Shopify's bug bounty programme.
  • Third-party services we integrate with. Report those to their operators.
  • Social engineering, denial of service, and anything else that degrades service for merchants or their customers.
  • Scanner output with no demonstrated impact.

Safe harbour

Security research that follows this policy is authorised, and we will not pursue legal action or refer you to law enforcement over it. Following this policy means two things: test against your own store (Shopify development stores are free, and Bird installs on them), and stop at proof. Do not access, modify, or delete anyone else's data, and if you reach it by accident, stop, tell us, and delete what you retrieved.

Not a security issue? For product bugs or billing, contact support instead. You will get a faster answer there.

Last updated: August 2026