Security and vulnerability disclosure
How to report a vulnerability and what to expect from us.
Last updated
On this page
Placeholder — not reviewed legal wording. TODO(compliance)
This page shows the section structure of the final document. Every section is filled in by a qualified adviser before launch. Nothing on this page states a commitment, a licence or a certification, and nothing on it should be relied on.
Reporting a vulnerability
TODO(compliance): reviewed text for “Reporting a vulnerability” — the reporting address, the encryption key to use, and the detail that makes a report actionable.
Scope
TODO(compliance): reviewed text for “Scope” — the domains, the API and the hosted payment page.
Out of scope
TODO(compliance): reviewed text for “Out of scope” — findings we will close without action, including reports generated by a scanner with no demonstrated impact.
What we ask
TODO(compliance): reviewed text for “What we ask” — no access to data that is not yours, no denial of service, no social engineering, and time to fix before you publish.
What you can expect
TODO(compliance): reviewed text for “What you can expect” — acknowledgement, a triage decision, updates while the fix is in progress, and credit if you want it.
Safe harbour
TODO(compliance): reviewed text for “Safe harbour” — the commitment not to pursue a researcher who follows this policy in good faith.
Security practices
TODO(compliance): reviewed text for “Security practices”. The current summary, including encryption, access control, logging and testing cadence, is on the Trust Center.