Vulnerability Disclosure Policy

Last updated: 2026-08-27

Paypercut takes the security of its systems seriously. If you believe you have found a security vulnerability in one of our services, we want to hear about it.

This policy explains how to report an issue to us, what we ask of you, and what you can expect from us in return.

How to report

Email security@paypercut.co.

If you wish to encrypt your report, our PGP public key is published at https://paypercut.com/.well-known/pgp-key.txt

Fingerprint: 2C58 13C1 B467 EF47 BE32  78F7 4BA9 F7B0 A8CE FFFA

Please verify the fingerprint against the value above before use. Encryption is optional; an unencrypted initial report is fine, provided it follows the guidance below.

Your first message should contain only:

- a brief description of the issue;
- the affected domain, endpoint, or feature;
- the approximate date and time you observed it.

Do not include exploit code, proof-of-concept payloads, credentials, personal data, or any data captured from our systems in this first message. We will reply with a secure channel for the full technical detail.

Once that channel is open, please provide:

- clear, step-by-step reproduction instructions;
- screenshots or request/response examples, with any sensitive data redacted;
- your assessment of the impact;
- whether you accessed any non-public data while discovering the issue, and if so, what.

Scope

In scope:

- paypercut.io and its subdomains - our product platform, including the merchant dashboard, our public APIs, and our API documentation.
- paypercut.com - our corporate website. In scope only for issues arising from content and configuration we control, such as exposed data or files, misconfigured forms or redirects, or subdomain takeover. The website is hosted on a third-party platform; vulnerabilities in that platform itself are out of scope and should be reported to the platform vendor.

Out of scope:

- paypercut.co - our internal corporate domain, used for staff email and single sign-on. The services behind it are operated by third parties on our behalf. Report issues in those services to the relevant provider.
- The underlying platforms and infrastructure on which our services are hosted, as distinct from our own configuration of them.
- Systems operated by our other third-party providers, including our payment processors, acquirers, tokenisation providers, and hosting providers. Report issues in those systems to the respective provider(s) directly.
- Findings from automated scanners submitted without a demonstrated, service-specific impact.
- Missing security headers, TLS configuration preferences, SPF/DKIM/DMARC policy strength, cookie flags, and similar configuration observations, unless you can demonstrate a concrete exploit path.
- Rate limiting, CAPTCHA, and account lockout thresholds, absent demonstrated impact.
- Social engineering of our staff, merchants, partners, or providers.
- Physical security of our offices or personnel.
- Reports of software versions without a demonstrated vulnerability.
Rules of engagement
When testing, you must:

- act only against accounts and data that belong to you;
- stop immediately and notify us if you encounter data belonging to another party, and not access, copy, retain, modify, delete, or disclose it;
- avoid any activity that degrades, interrupts, or damages our services or the experience of our merchants and their customers;
- keep the issue confidential until we have confirmed it is resolved, or until 90 days have elapsed from your initial report, whichever is sooner.

You must not:

- perform denial-of-service, load, or stress testing;
- run automated vulnerability scanners or brute-force tooling against our systems;
- conduct social engineering, phishing, or physical intrusion;
- use a vulnerability, or the threat of its disclosure, to seek payment or any other benefit from Paypercut.
Rewards
Paypercut does not operate a bug bounty program and does not offer monetary rewards for vulnerability reports. This applies regardless of whether a finding is subsequently confirmed as valid.

We are happy to credit reporters publicly by name once an issue is resolved, if you would like us to. Let us know when you report. The decision as to whether we will publish anything about the issue and its resolution remains within our sole discretion.

We do not accept unsolicited commercial offers for penetration testing or security consulting through this channel. Such messages will not receive a reply.
What you can expect from us
- We will endeavour to acknowledge your report within two business days.
- We will tell you whether we have accepted the report as a valid finding.
- We will not take legal action against you in respect of your research, provided you have acted in good faith and in accordance with this policy.
- We will treat your personal data in accordance with our privacy notice which is published on our website.
Safe harbour
If you conduct your research in good faith and in compliance with this policy, we will regard it as genuine, will not initiate or support legal action against you in connection with it, and will make our position known if a third party brings action against you in respect of that research.

This policy does not authorise activity that is unlawful, and it does not bind third parties. This policy only applies to  systems and data belonging to Paypercut.
Contact
security@paypercut.co

PGP fingerprint: 2C58 13C1 B467 EF47 BE32  78F7 4BA9 F7B0 A8CE FFFA
Try Paypercut’s online payments demo.
See how your customers will pay - cards, wallets, links, and QR - before you sign up.