Skip to content
ProxyPay home

Security

Responsible disclosure.

If you have found a security problem, we want to hear about it before anyone else does. Write to security@proxypay.app.

01

How to report

Where
security@proxypay.app. The same contact in machine-readable form sits at /.well-known/security.txt.
What helps
The steps you took, the result, the result you expected, and the smallest reproduction you have. Captures and screenshots are welcome. Once the issue is demonstrated, that is far enough.
What we do
We acknowledge a report within five business days, tell you whether we can reproduce it, and keep you updated until it is closed. These are our targets during the pilot, not a contractual service level.
Credit
We are glad to credit you by name when a fix ships, if you want that.
Reward
No bounty programme exists at pilot stage, and this page says so rather than leaving it to be inferred.
02

Rules of engagement

Please do

  • Test only against systems that are clearly ours.
  • Use your own accounts and your own data.
  • Stop at proof — no pivoting, no persistence, nothing copied out.
  • Give us reasonable time to fix an issue before you publish.

Please do not

  • Touch data that belongs to someone else, in any way.
  • Point load, flood or denial-of-service tooling at anything of ours.
  • Approach our people or our premises. Test the software, not the humans.
  • Test a merchant’s vault, exchange account or devices. Those belong to the merchant and their vendors, not to us.

Out of scope at pilot stage

This website is a static site with no accounts, no database and no third-party requests. Findings that amount to missing headers on a page with no session, or to a theoretical issue with no reachable impact, are welcome but will usually be closed as accepted risk with an explanation.