Security

Vulnerability Disclosure Policy

If you have found a security flaw in VOLTA, the ShishaX app, or any ShishaX website, we want to hear from you. This page explains how to reach us, what we will do with your report, and what we ask of you in return.

Version 1.0 Effective 27 August 2026 Published by SHX Corporation

How to report

Send reports to

This address is monitored by our security contact. Please do not report vulnerabilities through social media, support tickets, or sales channels, as those routes are slower and less private.

What to include

The more of this you can give us, the faster we can act:

Please write to us in English.

What we will do

Our commitments once a report arrives
StageTimingWhat happens
Acknowledgement 3 business days We confirm we have your report and give you a reference.
Initial assessment 10 business days We tell you whether we can reproduce it, our severity view, and our intended next step.
Progress updates Every 14 days We keep you posted until the issue is resolved or formally closed.
Coordinated disclosure 90 days Our default window from acknowledgement to public disclosure. We will discuss extending or shortening it with you.

Where a flaw is being actively exploited, we may also be required to notify EU authorities under Article 14 of Regulation (EU) 2024/2847. That obligation exists regardless of the disclosure timeline we agree with you, and we will tell you if it applies.

Scope

In scope

  • VOLTA device firmware, including the Bluetooth and Wi-Fi interfaces
  • The ShishaX companion app for Android
  • SHX Browser (shxbrowser.com)
  • shishax.com and shishax.eu
  • wholesale.shishax.com
  • support.shishax.com
  • crew.shishax.com
  • checkout.shishax.eu

Out of scope

  • Denial of service, load testing, or anything that degrades service for other users
  • Social engineering of our staff, partners, or customers
  • Physical attacks on our premises or on our people
  • Findings from automated scanners with no demonstrated impact
  • Missing security headers or best-practice suggestions with no exploitable consequence
  • Email configuration issues on domains we do not send mail from
  • Third-party platforms we do not control, such as Shopify or Google Play

What we ask of you

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, we will not report you to law enforcement, and if a third party brings action against you over research conducted within these rules, we will make it known that you had our authorisation.

If you are unsure whether something is within scope, write to us first and ask.

Recognition

We do not currently run a paid bug bounty. We do credit researchers by name in our security advisories when a report leads to a fix, unless you would rather stay anonymous. Tell us which you prefer when you report.

Security update support period

We provide security updates for VOLTA for at least five years from the date the last unit of a given model was placed on the market. Security updates are free of charge and are delivered over the air through the ShishaX app.