Skip to content
Sandbox open: magic test cards, hosted checkout and signed webhooks · 55 payment methods in the catalogue, cards to crypto · Built and hosted in the EEA · Read the API reference at /developers

Sandbox open: magic test cards, hosted checkout and signed webhooks

Security and vulnerability disclosure

How to report a vulnerability and what to expect from us.

Last updated

On this page

Placeholder — not reviewed legal wording. TODO(compliance)

This page shows the section structure of the final document. Every section is filled in by a qualified adviser before launch. Nothing on this page states a commitment, a licence or a certification, and nothing on it should be relied on.

Reporting a vulnerability

TODO(compliance): reviewed text for “Reporting a vulnerability” — the reporting address, the encryption key to use, and the detail that makes a report actionable.

Scope

TODO(compliance): reviewed text for “Scope” — the domains, the API and the hosted payment page.

Out of scope

TODO(compliance): reviewed text for “Out of scope” — findings we will close without action, including reports generated by a scanner with no demonstrated impact.

What we ask

TODO(compliance): reviewed text for “What we ask” — no access to data that is not yours, no denial of service, no social engineering, and time to fix before you publish.

What you can expect

TODO(compliance): reviewed text for “What you can expect” — acknowledgement, a triage decision, updates while the fix is in progress, and credit if you want it.

Safe harbour

TODO(compliance): reviewed text for “Safe harbour” — the commitment not to pursue a researcher who follows this policy in good faith.

Security practices

TODO(compliance): reviewed text for “Security practices”. The current summary, including encryption, access control, logging and testing cadence, is on the Trust Center.