Vulnerability Disclosure Policy
If you have found a security flaw in Payco, we want to hear about it, and this page tells you exactly how to tell us and what to expect back. It is the policy referenced by /.well-known/security.txt.
How to report
Email support@mypayco.com with "Security" in the subject line, or call +1 424-230-7212. Please include what you found, the URL or endpoint, the steps to reproduce it, and what an attacker could do with it. A short proof-of-concept is worth more than a scanner report.
We do not run a paid bug bounty. We will credit you by name in our release notes if you would like us to, and we will tell you when the issue is fixed.
What we commit to
- We will acknowledge your report within 3 business days and give you a single point of contact.
- We will tell you our assessment within 10 business days — whether we consider it a vulnerability, how severe we think it is, and when we expect to fix it.
- We will keep you updated until it is closed, and tell you when the fix is live.
- We will not take legal action against you for research conducted in good faith under this policy, and we will not ask your employer or your ISP to. If a third party brings action against you for work that followed this policy, we will make it known that it was authorised.
In scope
payco.aiand everything served from it, including our API under/api/.- Our authentication and session handling, and the permission model that separates merchants, agents, partners and staff.
- Anything that exposes another person's data, lets you act as them, or lets you read or write records you should not reach.
Out of scope, and please do not do these
- Do not access, modify or delete data that is not yours. If a flaw gives you access to someone else's records, stop, record only what you need to prove it, and tell us.
- No denial of service, load testing, or volumetric attacks against production.
- No social engineering of our staff, merchants, partners or sponsor banks, and no physical attacks on our offices.
- No spam or automated form submission against our application funnel — real applications are read by people.
- Reports that consist only of a scanner's output, a missing header with no demonstrated impact, or a best-practice observation without a described attack. We read them, but they are not vulnerabilities.
- Third-party services we do not control. Our service providers are named in our privacy policy; report issues in their products to them.
Safe harbour
Research that follows this policy is authorised. We consider it lawful, we will not pursue or support a claim under the Computer Fraud and Abuse Act or California Penal Code §502 for it, and we will not treat it as a breach of our Terms of Use. If you are unsure whether something is in scope, ask us first at the address above — asking is always in scope.
Please give us time
We ask that you give us 90 days from your report before publishing, or until the fix is live if that is sooner. If we disagree about severity or timing we will say so and explain why, rather than going quiet.