# Help us keep Payle secure. Canonical: https://www.usepayle.com/bugbounty Language: en Summary: Report a security vulnerability in Payle. What we look for, what makes a good report, the rules of responsible disclosure and how rewards work. Security is a shared responsibility. If you discover a vulnerability in Payle, we want to hear from you. [Report a vulnerability](mailto:security@usepayle.com) Responsible disclosure · Security researchers welcome Built for autonomous payments. Designed for controlled access. ## Find something? Tell us. We believe security improves when researchers, developers and companies work together. If you have discovered a security vulnerability affecting Payle, our infrastructure, our website, our APIs or our products, please report it responsibly. Our security team investigates every valid submission. ## What we are looking for Authentication and authorization Broken access control, privilege escalation, authentication bypasses. Payments and financial data Issues affecting transactions, payment authorization, balances, cards or financial information. API and infrastructure API vulnerabilities, server-side issues, exposed credentials, cloud infrastructure vulnerabilities. Privacy and data Unauthorized access to personal or sensitive user data. Web and application security XSS, CSRF, SSRF, injection, account takeover and other application-level vulnerabilities. ## What makes a good report? A useful report helps us reproduce and understand the issue quickly. - Clear description of the vulnerability - Affected URL, endpoint or component - Steps to reproduce - Proof of concept where appropriate - Security impact - Any relevant screenshots, requests or logs Please do not access, modify, download or delete data that does not belong to you. ## Responsible disclosure Please give us a reasonable opportunity to investigate and remediate a vulnerability before publicly disclosing it. Do not intentionally access another user’s account, expose private information, disrupt our services, or perform actions that could cause financial harm. Never test against real financial transactions or attempt to move funds that are not yours. ## Rewards Eligible vulnerabilities may qualify for a reward based on severity, impact and the quality of the report. Rewards are determined at Payle’s discretion and may vary depending on the vulnerability and the affected system. Found a vulnerability? Help us make Payle safer for everyone. [Report a vulnerability](mailto:security@usepayle.com) [security@usepayle.com](mailto:security@usepayle.com)