Security
reporting a problem with this website · last updated September 17, 2026
The short version
Found a security problem with this website? Tell us first, before you tell anyone else. Email info@skylandcannabis.com with Security report in the subject line, or call (828) 222-4367 and ask for Nick.
This page and /.well-known/security.txt say the same thing in two formats: one for a person, one for the tools that look for a file at a fixed address.
What this page covers
Everything below is about skylandcannabis.com: the shop you are reading, the pages under it, and the ordering API behind it:
- this website and everything served from it;
- the ordering, checkout and account endpoints the pages call;
- the certificate library at /coa/library;
- the admin panel, if you have found a way into it that you should not have.
What it does not cover
Several companies run parts of this shop, and a problem in their systems is theirs to fix and theirs to hear about first. We cannot act on a report about any of these, and we would rather you did not lose time telling us instead of them:
- Square: the product catalog, the stock counts and the order records.
- Authorize.Net: card processing. No card number ever reaches this website: the card fields are the gateway’s own and the browser sends them straight to it.
- Cloudflare: the bot check on the checkout.
- Google Drive: where the certificate files are kept before we copy them onto this site.
- The radio stations the shop can play, which are other people’s services and are named on the privacy policy.
Anything that happens inside the shop on Eagle Street, rather than on this website, is not a matter for this page either. Call us or come in.
What to put in a report
Whatever you have. A message that says only “your site is vulnerable” is one we cannot act on, and one we cannot tell apart from the several of those we get a month. The three things that make a report usable are:
- the address of the page or endpoint;
- what you did, in enough detail that we can do it too;
- what happened that should not have.
Please send it as text or as an attachment we can open without an account. We read reports ourselves (this is a small shop, not a security team), so plain English beats a scanner’s export.
We do not run a paid bug bounty. We are grateful for reports and we say so, and we would rather say that here than have anybody spend an afternoon on the expectation of a payment that is not coming.
What happens next
A person reads it, and we write back to tell you what we found and what we did. We will not pretend to a schedule we cannot keep: this is a shop with a website, not a rota of engineers, and an acknowledgement that arrives late but from somebody who has actually looked is worth more than an automatic one.
If you would like to be named once a problem is fixed, say so and we will. If you would rather not be, that is the default.