Security
Responsible disclosure
How to report a vulnerability in the Paycux platform, and what happens after you do.
How to report a vulnerability
Send the report to the security address listed in the console under Help, with enough detail for us to reproduce it: the endpoint or flow, the steps, and what you observed versus what you expected.
You do not need a proof-of-concept exploit. A clear description of the flaw is enough to start.
Guidelines for responsible research
Test against your own project in staging. Do not access, modify or retain data belonging to anyone else, and stop as soon as you have confirmed the issue.
- Use your own accounts and your own test data
- Do not run denial-of-service or load tests
- Do not use social engineering against staff or customers
- Give us a reasonable window before publishing
Feedback and communication
We acknowledge reports within one business day and give you an assessment within five. If we disagree that something is a vulnerability, we will say why rather than going quiet.
We agree a disclosure date with you, credit you in the advisory unless you prefer otherwise, and tell you when the fix ships.
Report something
Reports go straight to the security team, not to a general inbox.