Security

Vulnerability Disclosure Policy

If you have found a security flaw in VOLTA, the ShishaX app, or any ShishaX website, we want to hear from you. This page explains how to reach us, what we will do with your report, and what we ask of you in return.

Version 1.0 Effective 27 August 2026 Published by SHX Corporation

How to report

Send reports to

This address is monitored by our security contact. Please do not report vulnerabilities through social media, support tickets, or sales channels, as those routes are slower and less private.

What to include

The more of this you can give us, the faster we can act:

  • What the issue is and what an attacker could do with it
  • Which product, domain, or app version is affected
  • For VOLTA, the firmware version and hardware revision if you have them
  • Steps to reproduce, ideally enough that we can repeat it ourselves
  • Any proof of concept code, logs, or screenshots
  • Whether you intend to publish, and when

Please write to us in English.

What we will do

Our commitments once a report arrives
StageTimingWhat happens
Acknowledgement 3 business days We confirm we have your report and give you a reference.
Initial assessment 10 business days We tell you whether we can reproduce it, our severity view, and our intended next step.
Progress updates Every 14 days We keep you posted until the issue is resolved or formally closed.
Coordinated disclosure 90 days Our default window from acknowledgement to public disclosure. We will discuss extending or shortening it with you.

Where a flaw is being actively exploited, we may also be required to notify EU authorities under Article 14 of Regulation (EU) 2024/2847. That obligation exists regardless of the disclosure timeline we agree with you, and we will tell you if it applies.

Scope

In scope

  • VOLTA device firmware, including the Bluetooth and Wi-Fi interfaces
  • The ShishaX companion app for Android
  • SHX Browser (shxbrowser.com)
  • shishax.com and shishax.eu
  • wholesale.shishax.com
  • support.shishax.com
  • crew.shishax.com
  • checkout.shishax.eu

Out of scope

  • Denial of service, load testing, or anything that degrades service for other users
  • Social engineering of our staff, partners, or customers
  • Physical attacks on our premises or on our people
  • Findings from automated scanners with no demonstrated impact
  • Missing security headers or best-practice suggestions with no exploitable consequence
  • Email configuration issues on domains we do not send mail from
  • Third-party platforms we do not control, such as Shopify or Google Play

What we ask of you

  • Only test against devices and accounts that belong to you
  • Do not access, modify, or download data belonging to anyone else. If you come across personal data, stop and tell us
  • Do not disrupt our services or degrade the experience for other users
  • Give us a reasonable chance to fix the issue before you publish
  • Do not use the finding for extortion, and do not condition disclosure on payment

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, we will not report you to law enforcement, and if a third party brings action against you over research conducted within these rules, we will make it known that you had our authorisation.

If you are unsure whether something is within scope, write to us first and ask.

Recognition

We do not currently run a paid bug bounty. We do credit researchers by name in our security advisories when a report leads to a fix, unless you would rather stay anonymous. Tell us which you prefer when you report.

Security update support period

We provide security updates for VOLTA for at least five years from the date the last unit of a given model was placed on the market. Security updates are free of charge and are delivered over the air through the ShishaX app.

Who we are

ManufacturerSHX Corporation, 1602 Lockness Place, Torrance, California 90501, United States of America
Security contactsecurity@shishax.com
EU importerAndrés Felipe Duque Alvarez, El Masnou, Barcelona, Spain. NIF 60928520W, EORI ES-Y9118541K

This policy is published in accordance with the coordinated vulnerability disclosure requirement in Annex I, Part II of Regulation (EU) 2024/2847, the Cyber Resilience Act. A machine-readable version is available at shishax.eu/.well-known/security.txt.

ShishaX is a brand of SHX Corporation  ·  Version 1.0  ·  Last reviewed 27 August 2026  ·  security@shishax.com