Help us keep Payle secure.
Security is a shared responsibility. If you discover a vulnerability in Payle, we want to hear from you.
Report a vulnerabilityResponsible disclosure · Security researchers welcome
Built for autonomous payments. Designed for controlled access.
Find something? Tell us.
We believe security improves when researchers, developers and companies work together.
If you have discovered a security vulnerability affecting Payle, our infrastructure, our website, our APIs or our products, please report it responsibly. Our security team investigates every valid submission.
What we are looking for
Authentication and authorization
Broken access control, privilege escalation, authentication bypasses.
Payments and financial data
Issues affecting transactions, payment authorization, balances, cards or financial information.
API and infrastructure
API vulnerabilities, server-side issues, exposed credentials, cloud infrastructure vulnerabilities.
Privacy and data
Unauthorized access to personal or sensitive user data.
Web and application security
XSS, CSRF, SSRF, injection, account takeover and other application-level vulnerabilities.
What makes a good report?
A useful report helps us reproduce and understand the issue quickly.
- Clear description of the vulnerability
- Affected URL, endpoint or component
- Steps to reproduce
- Proof of concept where appropriate
- Security impact
- Any relevant screenshots, requests or logs
Please do not access, modify, download or delete data that does not belong to you.
Responsible disclosure
Please give us a reasonable opportunity to investigate and remediate a vulnerability before publicly disclosing it.
Do not intentionally access another user’s account, expose private information, disrupt our services, or perform actions that could cause financial harm.
Never test against real financial transactions or attempt to move funds that are not yours.
Rewards
Eligible vulnerabilities may qualify for a reward based on severity, impact and the quality of the report.
Rewards are determined at Payle’s discretion and may vary depending on the vulnerability and the affected system.