We are a PCI QSA company. Security researchers who report issues to us in good faith are welcome, and we will work with you until the issue is resolved.
Good-faith research that follows this policy will not lead to legal action or a report to law enforcement from us.
Valid reports earn a verifiable Certificate of Recognition, issued in your name or anonymously — your choice.
We do not run a paid bounty. For valid reports we can send a printed T-shirt and tote bag at our discretion.
Never send us live cardholder data, credentials, or personal data belonging to anybody else.
Timelines start from the acknowledgement email that carries your report reference.
All reports come through our contact form so every submission is logged with a unique reference you can quote in follow-ups. Choose Responsible vulnerability disclosure as the topic.
Our thanks to the researchers below, who reported issues to us responsibly and gave us time to fix them. Listed newest first, with the reporter's consent.