If you have found a security flaw in VOLTA, the ShishaX app, or any ShishaX website, we want to hear from you. This page explains how to reach us, what we will do with your report, and what we ask of you in return.
This address is monitored by our security contact. Please do not report vulnerabilities through social media, support tickets, or sales channels, as those routes are slower and less private.
The more of this you can give us, the faster we can act:
Please write to us in English.
| Stage | Timing | What happens |
|---|---|---|
| Acknowledgement | 3 business days | We confirm we have your report and give you a reference. |
| Initial assessment | 10 business days | We tell you whether we can reproduce it, our severity view, and our intended next step. |
| Progress updates | Every 14 days | We keep you posted until the issue is resolved or formally closed. |
| Coordinated disclosure | 90 days | Our default window from acknowledgement to public disclosure. We will discuss extending or shortening it with you. |
Where a flaw is being actively exploited, we may also be required to notify EU authorities under Article 14 of Regulation (EU) 2024/2847. That obligation exists regardless of the disclosure timeline we agree with you, and we will tell you if it applies.
If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, we will not report you to law enforcement, and if a third party brings action against you over research conducted within these rules, we will make it known that you had our authorisation.
If you are unsure whether something is within scope, write to us first and ask.
We do not currently run a paid bug bounty. We do credit researchers by name in our security advisories when a report leads to a fix, unless you would rather stay anonymous. Tell us which you prefer when you report.
We provide security updates for VOLTA for at least five years from the date the last unit of a given model was placed on the market. Security updates are free of charge and are delivered over the air through the ShishaX app.
| Manufacturer | SHX Corporation, 1602 Lockness Place, Torrance, California 90501, United States of America |
| Security contact | security@shishax.com |
| EU importer | Andrés Felipe Duque Alvarez, El Masnou, Barcelona, Spain. NIF 60928520W, EORI ES-Y9118541K |
This policy is published in accordance with the coordinated vulnerability disclosure requirement in Annex I, Part II of Regulation (EU) 2024/2847, the Cyber Resilience Act. A machine-readable version is available at /.well-known/security.txt.