Skip to content

PerionPayments

Report a security concern

Give the team enough context to investigate without exposing sensitive payment or account data.

What to include

Affected public URL, observed behavior, time in CAT or UTC, and steps that demonstrate the issue safely. Include only the minimum redacted proof.

What to leave out

Passwords, private keys, wallet PINs, one-time codes, full card numbers, customer identifiers and raw provider payloads.

Where to report

Email security@perionpayments.com. This is the reporting address published in security.txt.

Read the scope and stop conditions below before testing. Stop immediately if another person’s data, money movement or service availability is at risk.

Response expectations

The published policy targets acknowledgement in one business day, initial triage in three business days, and a material update every five business days. Severity and safe deployment determine the correction plan.

Read the published disclosure policy, scope and stop conditions
Vulnerability disclosure

Tell us clearly.
Test us carefully.

We welcome good-faith reports that help protect merchants and payers. Minimise data, stop before money or availability is at risk, and give us a reproducible path.

Version 1.0Effective 1 August 2026Review by 1 November 2026
Response targets
Acknowledgement
1 business day
Initial triage
3 business days
Material update
Every 5 business days

These are disclosure-process targets, not a bounty or a promise of remediation within a fixed period. Severity and safe deployment govern the correction plan.

Good-faith boundary

In scope—and where to stop.

In scope

  • Public API, hosted checkout, payment links, dashboard and console ingress
  • Authentication, authorization, tenant isolation, webhook verification, and exposed sensitive data
  • Published PerionPayments-owned origins listed on this site or in security.txt

Stop and report

  • Any access to another person's data or merchant environment
  • Any action that could move money, send a payer prompt, alter evidence, or degrade service
  • Any secret, provider credential, or production payload—retain only the minimum redacted proof

Out of scope

  • Social engineering, physical intrusion, denial of service, spam, automated bulk scanning, and third-party systems
  • Missing headers without exploitable impact, clickjacking on non-sensitive static pages, and version-only reports
  • No paid bounty is offered until operational maturity supports one

Safe harbour is evidence-bound too.

PerionPayments will treat compliant, good-faith research as authorized within this policy and will not pursue action solely for that research. This does not authorize breaking law, touching third-party systems, retaining data, or continuing after a stop request. Formal legal review remains a pilot publication gate.

Read machine-readable security.txt →
Start a security reportOpens your email app. You can also copy the address above.