Report a Security Issue
Report a Security Issue
Last updated: September 5, 2026
If you have found a security vulnerability affecting peaulon.com, we want to hear from you. This page explains how to report it, what happens next, and what we ask of you while we fix it.
How to Report
Email info@peaulon.com with “Security Report” in the subject line. Please do not post vulnerability details publicly, on social media or in a support chat before we have had a chance to respond.
Include as much of the following as you can:
- The type of issue, for example injection, authentication bypass, exposed data, misconfiguration
- The exact URL, endpoint or page affected
- Step-by-step instructions to reproduce it
- Proof of concept code, screenshots or a short screen recording
- Your assessment of the impact and who could be affected
- Browser, operating system and the date and time you tested
- How you would like to be credited, if you want credit
Our Response Commitment
| Stage | Target |
|---|---|
| Acknowledge your report | Within 2 business days |
| Initial triage and severity assessment | Within 5 business days |
| Progress updates | Every 7 days until closed |
| Fix for critical issues | Within 7 days of confirmation |
| Fix for high and medium issues | Within 30 days of confirmation |
We will tell you when the issue is fixed and, if you want it, credit you publicly once the fix is live.
In Scope
- peaulon.com and its subdomains
- The checkout and order flow
- Customer accounts, authentication and session handling
- Contact and enquiry forms
- Our email authentication configuration, including SPF, DKIM and DMARC
Out of Scope
- Third-party platforms and services we do not control, including payment processors and shipping carriers. Report those to the vendor directly.
- Findings from automated scanners with no demonstrated exploit
- Missing security headers or best-practice recommendations with no working attack path
- Denial of service, volumetric or brute-force load testing
- Social engineering, phishing or physical attacks against our staff, customers or premises
- Self-XSS, clickjacking on pages with no sensitive action, and issues that require a fully compromised device
- Reports about outdated software versions with no proven exploitable path on our site
Ground Rules for Testing
Test only against your own accounts and your own data. While researching, please:
- Do not access, modify, download or retain any other person’s data. If you encounter customer data, stop immediately, do not save it, and tell us what you saw.
- Do not degrade service, run automated scans at volume, or attempt denial of service.
- Do not place fraudulent orders or attempt to manipulate pricing to complete a purchase.
- Do not use social engineering against our team or our suppliers.
- Use the minimum access needed to demonstrate the issue, then stop.
- Give us reasonable time to fix the issue before disclosing it anywhere.
If you follow these rules in good faith, we will not pursue legal action over your research and we will work with you cooperatively.
Bounty
We do not currently run a paid bug bounty programme. We do offer public credit on request, a written acknowledgement you can reference, and store credit for significant findings at our discretion. We would rather say this plainly than have you spend time expecting a payout.
For Customers: Suspicious Emails and Fake Sites
Peaulon will never email or call you asking for your full card number, your CVV, your account password or a gift card payment. If you receive a message claiming to be from us that asks for any of those, do not reply to it. Forward it to info@peaulon.com and we will confirm whether it is genuine.
- Genuine emails from us come from an address ending in @peaulon.com.
- Our only website is https://peaulon.com/. Look closely at the spelling in any link before you click.
- We never ask for payment outside our own checkout, and we never request payment by wire transfer or cryptocurrency.
If you think your Peaulon account has been accessed by someone else, change your password immediately and contact us so we can review recent activity on the account.
Related Pages
Privacy Policy · Billing Policy · Terms of Service
Contact Details
- Store Name: Peaulon
- Website: https://peaulon.com/
- Address: 1688 N Pricetown Rd, Diamond, OH 44412, United States
- Phone: +1 (330) 309-3528
- Email: info@peaulon.com
- Business Hours: Monday to Friday, 9:00 AM to 5:00 PM (Eastern Time)
- Live Chat Support: 24/7 on peaulon.com