Skip to content

Vulnerability Disclosure Policy

Last updated: September 13, 2026

If you have found a security flaw in Payco, we want to hear about it, and this page tells you exactly how to tell us and what to expect back. It is the policy referenced by /.well-known/security.txt.

How to report

Email support@mypayco.com with "Security" in the subject line, or call +1 424-230-7212. Please include what you found, the URL or endpoint, the steps to reproduce it, and what an attacker could do with it. A short proof-of-concept is worth more than a scanner report.

We do not run a paid bug bounty. We will credit you by name in our release notes if you would like us to, and we will tell you when the issue is fixed.

What we commit to

In scope

Out of scope, and please do not do these

Safe harbour

Research that follows this policy is authorised. We consider it lawful, we will not pursue or support a claim under the Computer Fraud and Abuse Act or California Penal Code §502 for it, and we will not treat it as a breach of our Terms of Use. If you are unsure whether something is in scope, ask us first at the address above — asking is always in scope.

Please give us time

We ask that you give us 90 days from your report before publishing, or until the fix is live if that is sooner. If we disagree about severity or timing we will say so and explain why, rather than going quiet.

Payment card data: Payco is a registered MSP/ISO and does not store card numbers in this platform. If you believe you have found cardholder data, stop immediately and call the number above — that path has reporting obligations to our sponsor banks and the card networks that run on a shorter clock than this policy.