Report a Security Issue

At Lexarox, the security and privacy of our customers and systems are top priorities. We value the role of independent security researchers and the cyber security community in helping us keep our online store safe.

If you believe you have discovered a security vulnerability or flaw in our website, systems, or services, we encourage you to report it to us as soon as possible.

1. How to Report a Vulnerability

To report a security concern or vulnerability, please send an email to our dedicated security contact:

  • Security Email: support@lexarox.shop

  • Email Subject Line: [Security Vulnerability Report] - Brief Description

To help us assess and address the issue efficiently, please include the following details in your report:

  • A detailed description of the vulnerability and its potential impact.

  • Steps to reproduce the issue (including proof-of-concept scripts, HTTP requests, or screenshots where applicable).

  • The specific URLs, pages, parameters, or components affected.

  • Your contact information (if you wish to be credited or contacted for follow-up questions).

2. Responsible Disclosure Guidelines

When conducting security research on our store or reporting an issue, we ask that you adhere to the following principles:

  • Do No Harm: Do not access, modify, delete, or exfiltrate customer personal data, order histories, or sensitive business details.

  • Avoid Service Disruption: Do not perform Denial of Service (DoS/DDoS) attacks, spamming, or automated high-frequency scanning that could degrade site performance for legitimate users.

  • Privacy First: If you encounter customer data, stop immediately, purge any local copies, and report the issue to us without accessing further data.

  • Confidentiality: Allow us reasonable time (typically up to 30 days) to investigate and patch the issue before publicly disclosing any details.

  • No Social Engineering / Phishing: Do not attempt phishing, social engineering, or physical attacks against our employees, warehouse staff, or infrastructure.

3. Out-of-Scope Issues

The following issues are generally considered out of scope unless they demonstrate direct, severe exploitability:

  • Reports from automated scanners without a practical proof-of-concept.

  • Missing security headers or HTTP flags (e.g., CSP, HSTS, X-Frame-Options) without a working exploit path.

  • Clickjacking on non-sensitive pages without state-changing actions.

  • Software version disclosures without a working exploit.

  • Email spoofing risks due to missing or permissive SPF/DKIM/DMARC records (unless part of a larger chain).

  • Third-party embedded tools or services not controlled by Lexarox.

4. Our Commitment to Security Researchers

If you act in good faith and follow these disclosure guidelines:

  • Safe Harbor: We will not initiate legal action or report you to law enforcement regarding your security research.

  • Prompt Communication: We will acknowledge receipt of your report within 1–2 business days and keep you updated as we work on a resolution.

  • Recognition: With your consent, we are happy to acknowledge your help and contribution once the vulnerability is resolved.

5. Contact Information

For non-security or general customer service inquiries (order status, returns, billing), please refer to our standard support channels:

  • Company Name: Lexarox

  • Security & Support Email: support@lexarox.shop

  • Phone: +44 333 666 6111

  • Address: 6 Norris Dr, Birmingham, B33 8DX, United Kingdom

  • Business Hours: Monday–Friday, 9:00 AM–5:00 PM GMT