Vulnerability disclosure

Tell us clearly.
Test us carefully.

We welcome good-faith reports that help protect merchants and payers. Minimise data, stop before money or availability is at risk, and give us a reproducible path.

Contact

security@perionpayments.com

Send the affected hostname or public ID, steps, observed impact, and a safe proof. Do not email credentials, full payer data, raw provider payloads, or unredacted production evidence.

Start a security report →
Response targets
Acknowledgement
1 business day
Initial triage
3 business days
Material update
Every 5 business days

These are disclosure-process targets, not a bounty or a promise of remediation within a fixed period. Severity and safe deployment govern the correction plan.

Good-faith boundary

In scope—and where to stop.

In scope

  • Public API, hosted checkout, payment links, dashboard and console ingress
  • Authentication, authorization, tenant isolation, webhook verification, and exposed sensitive data
  • Published PerionPayments-owned origins listed on this site or in `security.txt`

Stop and report

  • Any access to another person's data or merchant environment
  • Any action that could move money, send a payer prompt, alter evidence, or degrade service
  • Any secret, provider credential, or production payload—retain only the minimum redacted proof

Out of scope

  • Social engineering, physical intrusion, denial of service, spam, automated bulk scanning, and third-party systems
  • Missing headers without exploitable impact, clickjacking on non-sensitive static pages, and version-only reports
  • No paid bounty is offered until operational maturity supports one

Safe harbour is evidence-bound too.

PerionPayments will treat compliant, good-faith research as authorized within this policy and will not pursue action solely for that research. This does not authorize breaking law, touching third-party systems, retaining data, or continuing after a stop request. Formal legal review remains a pilot publication gate.

Read machine-readable security.txt →