CryptoPayrlegal
HomeDocs
← Legal centre

Vulnerability Disclosure Policy

Last updated: September 27, 2026

We want to hear about security problems in CryptoPayr before anyone else does. If you believe you have found a vulnerability, report it to us privately and give us a fair chance to fix it. This policy explains what is in scope, how to test without causing harm, and what you can expect from us in return. Our machine-readable contact file is published at /.well-known/security.txt.

How to report

Email [email protected]. A useful report includes:

  • The affected URL, API endpoint, plugin or component, and the vulnerability type;
  • Step-by-step instructions to reproduce it, with requests/responses, screenshots or a short proof of concept;
  • What an attacker could achieve, and under which conditions;
  • The account ID (usr_…) you tested with, and how we can reach you.

Please do not send vulnerability details through support tickets, live chat, social media or public issue trackers.

In scope

  • cryptopayr.com and its subdomains, including the merchant portal, hosted checkout, payment links, invoices, donation pages and the exchange;
  • The REST API (/api/v1), webhooks we send, and the popup checkout SDK;
  • Plugins and the white-label gateway we publish for download.

Issues we are most interested in: anything that moves, reserves or credits money incorrectly; access to another merchant's data, balance or keys; authentication or 2FA bypass; server-side request forgery; injection; stored or reflected cross-site scripting on authenticated or payment pages; and exposure of credentials or configuration.

Out of scope

  • Third-party services we rely on (blockchain networks, our upstream processor, card on-ramp providers, email and analytics vendors) — report those to the vendor;
  • Denial-of-service, load testing, or anything that degrades the Services for others;
  • Social engineering, phishing, or physical attacks against our staff, merchants or offices;
  • Findings with no demonstrated security impact, such as missing headers on non-sensitive pages, self-XSS, logout CSRF, software version disclosure, or rate limits on non-sensitive actions;
  • Reports produced solely by automated scanners without a verified, reproducible impact.

Rules of engagement

  • Test only against accounts you own. Use sandbox mode (sk_test_ keys) wherever possible, and keep any live-money testing to the smallest amounts needed.
  • Do not access, modify or delete data that isn't yours. If you reach someone else's data, stop, don't keep a copy beyond what the report needs, and tell us straight away.
  • Do not move, withhold or attempt to keep funds that aren't yours. Any value obtained through a vulnerability must be reported and returned.
  • Keep automated testing to a volume that can't disrupt the Services.
  • Keep the details confidential until we have fixed the issue and agreed a disclosure date with you.

Safe harbour

If you act in good faith and follow this policy, we consider your research authorised. We will not pursue legal action against you or report you to law enforcement for it, and if a third party brings a claim against you over research that complied with this policy, we will make it known that your work was authorised. This does not cover activity that breaches the rules above, harms our merchants or their customers, or breaks the law.

What you can expect from us

  • We aim to acknowledge your report within 5 business days;
  • We will confirm whether we can reproduce the issue, and keep you updated while we fix it;
  • We will tell you when it is resolved, and agree a coordinated disclosure date with you — normally within 90 days of your report;
  • With your permission, we will credit you publicly once the fix is live.

We do not currently run a paid bug bounty programme. Any reward for a report is at our discretion and depends on its impact and quality.

Contact

Security reports: [email protected]. For anything else, see Contact or Legal Inquiries.