PCiPCI Assessments Center
Security

Responsible vulnerability disclosure

We are a PCI QSA company. Security researchers who report issues to us in good faith are welcome, and we will work with you until the issue is resolved.

Safe harbour

Good-faith research that follows this policy will not lead to legal action or a report to law enforcement from us.

Recognition certificate

Valid reports earn a verifiable Certificate of Recognition, issued in your name or anonymously — your choice.

Swag, not bounties

We do not run a paid bounty. For valid reports we can send a printed T-shirt and tote bag at our discretion.

In scope

  • pciassessments.com and www.pciassessments.com
  • pciassessments.ai and www.pciassessments.ai
  • api.pciassessments.com (public API edge)
  • The authenticated portal: assessments, training, exams, reporting and Kai

Out of scope

  • Denial of service, volumetric or stress testing of any kind
  • Social engineering, phishing or physical attacks against staff or customers
  • Automated scanner output with no demonstrated impact
  • Missing best-practice headers or TLS configuration with no exploit path
  • Vulnerabilities in third-party services we do not operate
  • Attacks requiring a rooted device, malware, or a compromised end-user account

Rules of engagement

  1. 1Only test against accounts and data you own. Never access, modify or exfiltrate another user's data.
  2. 2Stop as soon as you have proof of concept. Do not pivot, escalate or persist.
  3. 3Never use live cardholder data. If you encounter any, stop immediately and tell us.
  4. 4Do not degrade our service or the experience of other users.
  5. 5Keep the finding confidential until we confirm it is remediated.

What to include in your report

  • • The affected URL, endpoint or feature
  • • Clear, reproducible steps and the request/response involved
  • • Your assessment of impact and severity
  • • Any screenshots or a short proof of concept
  • • Whether you want public credit, and the name or handle to use

Never send us live cardholder data, credentials, or personal data belonging to anybody else.

Our response timeline

Acknowledgement
Within 2 business days
Initial triage and severity
Within 5 business days
Remediation target (critical / high)
30 days
Remediation target (medium / low)
90 days
Public recognition
After the fix is deployed

Timelines start from the acknowledgement email that carries your report reference.

Submit a report

All reports come through our contact form so every submission is logged with a unique reference you can quote in follow-ups. Choose Responsible vulnerability disclosure as the topic.

Hall of fame

Our thanks to the researchers below, who reported issues to us responsibly and gave us time to fix them. Listed newest first, with the reporter's consent.

No public acknowledgements yet. Yours could be the first.