Security Policy
Customer Shopping & Platform Security
We partner with industry-leading providers to ensure your personal and payment information remains secure throughout your shopping experience.
-
Secure Credit Card Processing: Our store is hosted on Shopify, which is certified Level 1 PCI DSS compliant. This compliance ensures that all credit card data and sensitive information are transmitted with the highest standard of server-side encryption. We do not store your complete credit card information on our personal servers. You can read the Shopify Security Policy here.
-
SSL Encryption: Every page on our website uses SSL (Secure Sockets Layer) encryption. This creates an encrypted connection between your browser and our servers, preventing unauthorized third parties from intercepting your data.
-
Third-Party Integrations: We carefully vet all third-party applications, plugins, and integration APIs used on our storefront to minimize risk and protect account integrity.
Vulnerability Disclosure Policy
At Sawtooth Supplement Science, security is a top priority. We appreciate the work of independent security researchers and the community in helping us keep our systems, customer data, and online storefront safe.
If you believe you have discovered a security vulnerability in any Sawtooth Supplements property, we encourage you to report it to us as quickly as possible.
Safe Harbor Framework
If you conduct your research and disclosure in good faith and in compliance with this policy:
-
Legal Immunity: We will consider your research to be authorized, and we will not initiate or support legal action against you related to your research.
-
Collaboration: We will work with you to understand, validate, and remediate the reported issue promptly.
-
Protection: If a third party takes legal action against you for activities conducted under this policy, we will make it known that your actions were conducted in accordance with this policy.
Guidelines & Requirements
To qualify under Safe Harbor and ensure smooth resolution, please adhere to the following rules:
-
Prompt Reporting: Submit your report as soon as possible after discovering the vulnerability.
-
Privacy & Data Protection: Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Do not view, access, modify, or download user data beyond what is strictly necessary to demonstrate the proof-of-concept.
-
Confidentiality: Keep information about any discovered vulnerabilities confidential between yourself and Sawtooth Supplements until we have remediated the issue and granted explicit permission for disclosure.
-
Scope Limits: Do not execute attacks against third-party providers or integration APIs used by Sawtooth Supplements.
Out of Scope Activities
The following test methods and issue types are strictly out of scope:
-
Denial of Service (DoS or DDoS) attacks or resource exhaustion tests.
-
Spamming, social engineering, phishing, or physical security testing against Sawtooth Supplements employees, facilities, or infrastructure.
-
Content Spoofing, Missing HTTP Security Headers (without a working exploit), or SSL/TLS best practices configuration issues.
-
Automated scanner output without direct proof-of-concept demonstrating actionable vulnerability.
-
Vulnerabilities affecting outdated or unsupported browser/operating system versions.
How to Submit a Vulnerability Report
Send your findings to: [email protected]
To help us triage and respond quickly, please include:
-
Description: Clear explanation of the vulnerability and its potential impact.
-
Steps to Reproduce: Step-by-step instructions, PoC scripts, or screenshots/videos showing how to reproduce the issue.
-
Affected Assets: URLs, endpoints, parameters, or systems involved.
-
Contact Info: Your name or handle if you would like attribution in our acknowledgments.
Our Commitment to You
When you report an issue to us, we commit to:
-
Acknowledgment: Acknowledge receipt of your report within 2 business days.
-
Triage & Communication: Validate findings and provide regular updates regarding remediation progress.
-
Resolution: Work to patch validated issues within reasonable timeframes based on severity.
-
Recognition: Publicly acknowledge your contribution (with your permission) on our Security Hall of Fame once the vulnerability is resolved.
Note: Sawtooth Supplements does not currently offer a paid Bug Bounty reward program, but we deeply appreciate researcher contributions and acknowledge public credit for eligible reports.