Security

Report a Security Issue.
Help Us Keep It Tight.

If you have discovered a security vulnerability on loyalhit.com, we encourage you to report it immediately. Loyal Hit LLC takes the security of our platform, customer accounts, and payment information seriously. We review all legitimate reports and work quickly to resolve confirmed issues.

Last Updated July 2026
Acknowledgment 3 Business Days
Ground Rules

Fundamentals

If you follow the principles below when reporting a security issue to Loyal Hit LLC, we will not initiate legal action or enforcement investigations against you in response to your report.

We ask that you:

  1. Give us reasonable time to investigate and resolve the issue before public disclosure
  2. Do not access, modify, or expose private customer accounts without explicit permission
  3. Make a good-faith effort to avoid privacy violations, service interruptions, or data destruction
  4. Do not exploit the vulnerability for personal gain or to access sensitive customer information
  5. Comply with all applicable local, state, federal, and international laws
Program

Bug Bounty Program

Loyal Hit LLC values responsible security researchers who help us protect our customers and our ecommerce platform. Bounties are awarded at our sole discretion based on severity, exploitability, impact, and report quality.

To potentially qualify for a reward, you must:

  1. Follow all fundamentals listed above
  2. Submit a valid vulnerability that presents a genuine security risk
  3. Send your report directly to contact@loyalhit.com
  4. Disclose any accidental access to sensitive information during your testing
  5. Provide enough technical detail for our team to reproduce the issue
  6. Understand that investigation time depends on issue severity and complexity
  7. Agree that Loyal Hit LLC may publish resolved reports at our discretion
Bounties

Rewards

Rewards are based on the severity and business impact of the reported issue. The first valid report of a unique vulnerability receives the bounty. Duplicate reports may not be eligible.

Critical — $500

  • Remote Code Execution
  • Full account takeover
  • SQL Injection exposing customer data
  • Authentication bypass with admin access
  • Payment system compromise

High — $250

  • Stored XSS affecting customers
  • Disclosure of sensitive internal data
  • Privilege escalation
  • Insecure authentication/session handling
  • Local file inclusion

Medium — $100

  • Business logic flaws
  • CSRF on sensitive actions
  • IDOR vulnerabilities
  • Security misconfigurations
  • Unvalidated redirects

Low — Recognition

  • Open redirects
  • Reflected XSS
  • Low-risk information disclosure
  • Missing security headers
  • Minor misconfigurations
Out of Scope

Non-Reportable Issues

The following are generally considered out of scope and are not eligible for bounty rewards:

  • Denial of Service (DoS / DDoS) attacks or testing
  • Spam, phishing, or social engineering attacks
  • Physical security issues
  • Third-party plugin issues outside our direct control
  • Automated scanner reports without manual verification
  • Previously known or already reported vulnerabilities
Process

How to Submit a Report

Please send your report to contact@loyalhit.com using the subject line: Security Vulnerability Report – loyalhit.com

Your report should include:

  • A clear description of the vulnerability
  • Step-by-step instructions to reproduce the issue
  • The potential impact on customers or systems
  • Screenshots, videos, or proof-of-concept if available
  • Your contact information for follow-up communication

We aim to acknowledge valid reports within 3 business days and will keep you informed throughout the investigation process.

Contact Us

We typically respond within 1 business day — Mon–Sat, 10am–7pm EST

Business Hours

Mon – Sat: 10:00 AM – 7:00 PM EST
Sunday: Closed

Response time: within 1 business day (Mon–Sat, 10:00 AM – 7:00 PM EST)