Security

Security at SHY

Security work at SHY is continuous. This page covers how to report a vulnerability and, in plain language, how we protect the service.

Reporting a vulnerability

If you believe you have found a security vulnerability in SHY, email [email protected] with "Security report" in the subject. Include steps to reproduce and the impact you believe it has. We commit to acknowledging reports within 5 business days, keeping you informed while we investigate, and crediting reporters who wish to be credited once an issue is resolved.

Testing ground rules

Good-faith research within these rules will not be met with legal action by SHY.

How SHY protects data

SHY does not currently hold third-party certifications such as SOC 2 or ISO 27001, and does not claim them.

Last reviewed: August 19, 2026.