Reporting a vulnerability
Send suspected security vulnerabilities to [email protected] with a clear description, affected URL or component, reproduction steps, potential impact, and safe supporting evidence. Encrypt sensitive reports when an approved secure channel is available.
Protect users and data
Use the minimum testing necessary to demonstrate an issue. Stop immediately if you encounter personal information, financial information, credentials, payment authority, or another party’s confidential data. Do not retain, alter, transfer, or disclose that information.
Prohibited testing
Do not conduct denial-of-service activity, social engineering, phishing, credential stuffing, physical attacks, malware deployment, automated high-volume scanning, destructive testing, payment initiation, bank interaction, data exfiltration, or testing of third-party providers without their written authorization.
Demonstration credentials
Public demo credentials and device-local authenticator secrets are intentionally non-production. Their public availability is not a vulnerability unless the issue enables access to nonpublic systems or data.
Coordinated disclosure
Allow reasonable time for investigation and remediation before publishing information. Do not publicly disclose an unresolved issue, confidential correspondence, customer information, or details that could increase exploitation risk.
Our response
We aim to acknowledge a credible report, assess severity, coordinate follow-up, and communicate remediation status when appropriate. Response timing depends on impact, reproducibility, affected providers, and operational risk.
Good-faith research and authorization boundary
When research follows this policy, remains within scope that Pacorda, Inc. can authorize, avoids harm, and complies with law, we will consider it good-faith security research. This statement does not authorize testing of a bank, payment network, cloud provider, customer, or other third party; does not modify their terms; and is not a waiver of legal rights for harmful, reckless, extortionate, or unlawful conduct.
Recognition and rewards
Pacorda does not currently promise monetary rewards. Recognition, if any, is discretionary and requires consent. Do not include financial-account details in a report.