Security
Responsible disclosure.
If you have found a security problem, we want to hear about it before anyone else does. Write to security@proxypay.app.
01
How to report
- Where
- security@proxypay.app. The same contact in machine-readable form sits at /.well-known/security.txt.
- What helps
- The steps you took, the result, the result you expected, and the smallest reproduction you have. Captures and screenshots are welcome. Once the issue is demonstrated, that is far enough.
- What we do
- We acknowledge a report within five business days, tell you whether we can reproduce it, and keep you updated until it is closed. These are our targets during the pilot, not a contractual service level.
- Credit
- We are glad to credit you by name when a fix ships, if you want that.
- Reward
- No bounty programme exists at pilot stage, and this page says so rather than leaving it to be inferred.
02
Rules of engagement
Please do
- Test only against systems that are clearly ours.
- Use your own accounts and your own data.
- Stop at proof — no pivoting, no persistence, nothing copied out.
- Give us reasonable time to fix an issue before you publish.
Please do not
- Touch data that belongs to someone else, in any way.
- Point load, flood or denial-of-service tooling at anything of ours.
- Approach our people or our premises. Test the software, not the humans.
- Test a merchant’s vault, exchange account or devices. Those belong to the merchant and their vendors, not to us.
Out of scope at pilot stage
This website is a static site with no accounts, no database and no third-party requests. Findings that amount to missing headers on a page with no session, or to a theoretical issue with no reachable impact, are welcome but will usually be closed as accepted risk with an explanation.