Security & Responsible Disclosure
Responsibledisclosure policy
PayHalal takes the security of our systems and users’ data seriously. We value the work of security researchers who help us identify and fix vulnerabilities responsibly.
Report vulnerabilities
[email protected]How to report
Please send your report to [email protected], encrypted using our public PGP key.
Please send reports only to this address. Reports sent to general support channels may experience delays, as they are not routed directly to our security team.
To help us act quickly, please include:
- The IP address or URL of the affected system.
- A clear description of the vulnerability.
- Steps to reproduce the issue. The more complex the flaw, the more detail we need.
- Your contact details, at minimum an email address, so we can follow up.
What happens after you report
- You will receive an automated acknowledgement confirming we’ve received your report.
- We aim to provide a substantive first response within 10 business days.
- Reports are triaged and prioritized by severity. Lower-severity or duplicate findings may take longer to receive a full response.
- As a small team, we are not able to commit to a fixed remediation timeline or provide continuous status updates. We will update you at key milestones such as acknowledgement, validation, and resolution.
- If you haven’t heard from us within 10 business days, feel free to follow up on the same thread. Please avoid submitting duplicate reports through other channels, as this can cause delays.
Rules of engagement
- Act responsibly and do nothing beyond what is necessary to demonstrate the security flaw.
- Avoid sending malware.
- Avoid copying, changing, or deleting data in the system. A directory listing is an acceptable alternative to demonstrate access.
- Avoid modifying the system.
- Avoid repeatedly accessing the system or sharing access with others.
- Avoid brute-force attempts.
- Avoid denial-of-service attacks or social engineering.
- Do not test against live merchant or customer payment data. If you believe you’ve found a flaw involving real transaction data, stop immediately and report it. Do not attempt further verification using that data.
Out of scope
The following are not considered security risks and are not eligible for acknowledgement, as we have other controls or defense-in-depth measures in place:
- Absence or misconfiguration of DNS CAA records.
- Absence or misconfiguration of DNSSEC.
- Missing security headers without a demonstrated, working exploit.
- Clickjacking on pages with no sensitive actions.
- Self-XSS or issues requiring an unlikely victim action with no realistic attack path.
- Rate-limiting reports on non-authentication, non-payment endpoints.
- Reports generated solely by automated scanners without manual validation.
Disclosure
Please do not publicly disclose a reported vulnerability until we have confirmed it is resolved, or 90 days have passed since your report, whichever comes first. We’re happy to discuss coordinated disclosure timing if needed.
What you can expect from us
If you follow this policy:
- We will not pursue legal action against you for your notification.
- We will treat your report confidentially and will not share your personal details with third parties without your permission, unless required by law or court order.
- We’re a small team, and we genuinely appreciate the effort that goes into a well-documented report. We ask for a bit of patience on timelines in exchange for our commitment to actually read, triage, and act on what you send us.