Responsible disclosure

Tell Us Before Anyone Else

We handle payments, so a vulnerability in PaymentHood matters to every merchant on the platform. If you find one, report it privately and we will work it through with you. This page sets out exactly what we are asking for and what you get in return.

Scope

What You May Test

In scope
www.paymenthood.com, console.paymenthood.com, docs.paymenthood.com, the PaymentHood API, and our published integration plugins for WHMCS, WooCommerce, J2Commerce, VirtueMart and Phoca Cart.
Out of scope
Systems we do not operate. That includes your payment providers, our technology suppliers, marketplace listings, and any third-party service reachable from our pages. Report issues in those directly to their owners.
Not accepted
Denial of service and volumetric testing, social engineering of our staff or customers, physical attacks, spam or automated scanner output with no demonstrated impact, missing best-practice headers with no exploit path, and reports that only restate a public CVE without showing it affects us.
Rules of engagement

How to Test Without Causing Harm

These exist because real merchants take real money through this platform.

๐Ÿงช

Use your own test account

Sign up for a free account and test against that. Never test against an account, merchant, or dataset that is not yours.

๐Ÿ›‘

Stop at proof

Once you can demonstrate a vulnerability, stop. Do not pivot further, escalate, or pull more data than the minimum needed to show impact.

๐Ÿ”’

Do not keep what you find

If you encounter personal or cardholder data, stop immediately, tell us, and delete any copy you hold. Do not store, share, or publish it.

๐Ÿค

Give us time

Keep the issue private until we have shipped a fix or agreed a disclosure date with you. If we go quiet, chase us before going public.

Safe harbour

We Will Not Come After You

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue legal action against you, and we will not report you to law enforcement, for testing that stays within the scope and rules above.

If someone else brings a claim against you for research that followed this policy, tell us and we will confirm publicly that your testing was authorised. This protection covers what we control. It cannot extend to third parties, and it does not apply if you access other people's data, disrupt the service, or extort us.

What happens next

After You Send the Report

Acknowledgement
Within 3 business days, from a human, confirming we have the report.
Initial assessment
Within 10 business days we will tell you whether we could reproduce it, how we rate the severity, and roughly when we expect to fix it.
Progress updates
At least every 14 days until the issue is closed, so you are never left guessing.
Reward
We do not run a paid bug bounty. What we offer is a straight answer, a real fix, and public credit on this page if you want it. Say so in your report and we will name you, or keep you anonymous if you prefer.

A good report includes the affected URL or endpoint, the steps to reproduce it, what an attacker gains, and anything that helps us see it quickly. Screenshots and a short video help more than a scanner export.

Found something?

Send it to [email protected] with "Security Disclosure" in the subject line. Our machine-readable contact details are published at /.well-known/security.txt.