Security
Security and Vulnerability Reporting
Last updated: 1 September 2026
Report a security or privacy issue: email support@ceilr.com with Security in the subject line. You do not need an account, and you do not need to sign in to report an issue. Reports are welcome from anyone, including sellers, researchers and Amazon.
Who this page is for
This page describes how to report, and how CEILR responds to, a suspected security vulnerability, a privacy issue, or suspected misuse of Amazon-originated data. CEILR is operated by Arc Techno Pty Ltd.
How to report
Email support@ceilr.com with Security in the subject line. To help us assess a report quickly, please include as much of the following as you can:
- What you found, and why you believe it is a security or privacy issue.
- The affected surface — for example
ceilr.com,app.ceilr.com, or a specific page or endpoint. - Steps to reproduce, including any request or response detail you can share.
- The date and approximate time you observed it, and your timezone.
- Whether you believe any data was exposed, and to whom.
- How you would like to be credited, if you would like to be credited.
Please do not include another person's or seller's data in your report. Describe what you were able to reach rather than sending the data itself.
What happens after you report
Every report follows the same documented process.
- Acknowledgement. We confirm we have received your report, normally within 3 business days.
- Investigation. We reproduce and assess the issue, determine severity, and identify whether any personal information or Amazon-originated data was affected. We aim to complete an initial assessment within 10 business days and will tell you if it will take longer.
- Containment and remediation. We contain the issue, then remediate it. Where an issue is actively exploitable, containment takes priority over a complete fix, and we may restrict or disable the affected capability while we work.
- Notification. Where a confirmed incident affects personal information or Amazon-originated data, we notify the affected parties. Where the incident involves Amazon data, we notify Amazon. Where Australian law requires it, we notify the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. We do not stay silent about a confirmed breach that affects you.
- Tracking to closure. The report stays open until the fix is deployed and verified. We keep you updated while it is open and tell you when it is closed.
Reporting suspected misuse of Amazon data
If you believe CEILR has accessed, retained, shared or used Amazon-originated data in a way it should not have — including any use inconsistent with what CEILR publishes in its Privacy Policy — report it through the same channel, with Amazon data in the subject line. Reports of suspected Amazon-data misuse follow the process above and are escalated to Amazon where the report is substantiated.
Scope
In scope: the CEILR marketing site (ceilr.com), the CEILR application (app.ceilr.com) and the CEILR API. Also in scope: any issue that could expose one seller's workspace data to another, weaken authentication, or expose Amazon-originated data.
Out of scope: findings against third-party services CEILR uses, which should be reported to those providers; missing hardening headers with no demonstrated impact; automated scanner output without a working proof of concept; and reports whose only content is that a version number is visible.
Testing we ask you not to do
When investigating, please stay within these limits. They exist to protect sellers, not to discourage reports.
- Do not access, modify, download or retain any data belonging to another seller or user. If you reach data that is not yours, stop and tell us what you reached.
- Do not run denial-of-service or load tests, or anything that degrades service for others.
- Do not use social engineering, phishing, or physical intrusion against CEILR, its operator or its providers.
- Do not make an Amazon API request through CEILR that CEILR does not itself make, and do not attempt to use CEILR to write to a seller's Amazon account.
- Do not publicly disclose the issue until we have had a reasonable opportunity to remediate it.
Good-faith research
If you follow the limits above and report promptly, we will treat your research as good-faith, we will not pursue action against you for it, and we will work with you until the issue is closed. CEILR does not currently operate a paid bug-bounty programme, so please report because it is the right thing to do rather than in expectation of payment. We are glad to credit you publicly if you would like that.
Contact
Security and privacy reports: support@ceilr.com, subject line Security. This mailbox is monitored, and a report sent here reaches a person who can act on it.