Security

Responsible disclosure policy

We would much rather hear about a flaw from you than read about it somewhere else. This page tells you how to reach us, what we will do, and what we ask of you in return.

Applies to
shypayments.com and the ShyPay mailboxes listed on this site.
Last updated
Contact
security@shypayments.com

How to report

Email security@shypayments.com. Machine-readable contact details are published at /.well-known/security.txt.

Please include enough for us to reproduce the issue: the affected URL or address, the steps you took, what you observed, and why you believe it matters. A short proof of concept is worth a long description. Write in English if you can.

Scope

In scope: this website and its hosting configuration, our DNS and email configuration, and anything that would let someone impersonate ShyPay or tamper with what visitors to this site receive.

Out of scope: services operated by other companies, including hosting, email, domain registration, and the independent providers named on this site — report those to their own security teams. The ShyPay application is also out of scope, because it has not been released.

Reports that are purely the output of a scanner with no demonstrated impact, missing hardening headers with no exploitable consequence, reports about software versions without a working attack, and social-engineering or physical attacks against our people are not something we will treat as vulnerabilities.

What we ask of you

  • Give us a reasonable opportunity to fix the issue before you make it public.
  • Do not access, modify, or delete data that is not yours, and stop as soon as you have demonstrated the problem.
  • Do not degrade the service for others: no denial-of-service testing, no high-volume automated scanning, no spam.
  • Do not use social engineering, phishing, or physical intrusion against our people or our providers.
  • Comply with the law that applies to you.

What we commit to

  • We will acknowledge your report and tell you what we think of it in plain language.
  • We will keep you updated while we work on it, and tell you when it is fixed.
  • We will not pursue or support legal action against anyone acting in good faith within this policy, and we will treat such activity as authorised for the purposes of our terms of use.
  • We will credit you publicly if you would like to be credited, and leave you out of it if you would not.

There is no bug bounty

We do not run a paid bounty programme at this stage and we are not going to imply otherwise. If that changes, it will be announced here with terms attached. We recognise that this makes a report an act of goodwill, and we will treat it as one.

No audit or certification claims

ShyPay holds no security certification and has published no third-party security audit. We would rather say that plainly than let a badge imply something we have not earned. When an audit is carried out, it will be published here with the report attached.