Vulnerability Disclosure Policy
If you have found a security flaw in VOLTA, the ShishaX app, or any ShishaX website, we want to hear from you. This page explains how to reach us, what we will do with your report, and what we ask of you in return.
How to report
This address is monitored by our security contact. Please do not report vulnerabilities through social media, support tickets, or sales channels, as those routes are slower and less private.
What to include
The more of this you can give us, the faster we can act:
- What the issue is and what an attacker could do with it
- Which product, domain, or app version is affected
- For VOLTA, the firmware version and hardware revision if you have them
- Steps to reproduce, ideally enough that we can repeat it ourselves
- Any proof of concept code, logs, or screenshots
- Whether you intend to publish, and when
Please write to us in English.
What we will do
| Stage | Timing | What happens |
|---|---|---|
| Acknowledgement | 3 business days | We confirm we have your report and give you a reference. |
| Initial assessment | 10 business days | We tell you whether we can reproduce it, our severity view, and our intended next step. |
| Progress updates | Every 14 days | We keep you posted until the issue is resolved or formally closed. |
| Coordinated disclosure | 90 days | Our default window from acknowledgement to public disclosure. We will discuss extending or shortening it with you. |
Where a flaw is being actively exploited, we may also be required to notify EU authorities under Article 14 of Regulation (EU) 2024/2847. That obligation exists regardless of the disclosure timeline we agree with you, and we will tell you if it applies.
Scope
In scope
- VOLTA device firmware, including the Bluetooth and Wi-Fi interfaces
- The ShishaX companion app for Android
- SHX Browser (shxbrowser.com)
- shishax.com and shishax.eu
- wholesale.shishax.com
- support.shishax.com
- crew.shishax.com
- checkout.shishax.eu
Out of scope
- Denial of service, load testing, or anything that degrades service for other users
- Social engineering of our staff, partners, or customers
- Physical attacks on our premises or on our people
- Findings from automated scanners with no demonstrated impact
- Missing security headers or best-practice suggestions with no exploitable consequence
- Email configuration issues on domains we do not send mail from
- Third-party platforms we do not control, such as Shopify or Google Play
What we ask of you
- Only test against devices and accounts that belong to you
- Do not access, modify, or download data belonging to anyone else. If you come across personal data, stop and tell us
- Do not disrupt our services or degrade the experience for other users
- Give us a reasonable chance to fix the issue before you publish
- Do not use the finding for extortion, and do not condition disclosure on payment
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, we will not report you to law enforcement, and if a third party brings action against you over research conducted within these rules, we will make it known that you had our authorisation.
If you are unsure whether something is within scope, write to us first and ask.
Recognition
We do not currently run a paid bug bounty. We do credit researchers by name in our security advisories when a report leads to a fix, unless you would rather stay anonymous. Tell us which you prefer when you report.
Security update support period
We provide security updates for VOLTA for at least five years from the date the last unit of a given model was placed on the market. Security updates are free of charge and are delivered over the air through the ShishaX app.
Who we are
| Manufacturer | SHX Corporation, 1602 Lockness Place, Torrance, California 90501, United States of America |
| Security contact | security@shishax.com |
| EU importer | Andrés Felipe Duque Alvarez, El Masnou, Barcelona, Spain. NIF 60928520W, EORI ES-Y9118541K |
This policy is published in accordance with the coordinated vulnerability disclosure requirement in Annex I, Part II of Regulation (EU) 2024/2847, the Cyber Resilience Act. A machine-readable version is available at shishax.eu/.well-known/security.txt.

