What to include
Affected public URL, observed behavior, time in CAT or UTC, and steps that demonstrate the issue safely. Include only the minimum redacted proof.
What to leave out
Passwords, private keys, wallet PINs, one-time codes, full card numbers, customer identifiers and raw provider payloads.
Where to report
Email security@perionpayments.com. This is the reporting address published in security.txt.
Read the scope and stop conditions below before testing. Stop immediately if another person’s data, money movement or service availability is at risk.
Response expectations
The published policy targets acknowledgement in one business day, initial triage in three business days, and a material update every five business days. Severity and safe deployment determine the correction plan.
Read the published disclosure policy, scope and stop conditions
Vulnerability disclosureTell us clearly.
Test us carefully.
We welcome good-faith reports that help protect merchants and payers. Minimise data, stop before money or availability is at risk, and give us a reproducible path.
Version 1.0Effective 1 August 2026Review by 1 November 2026
ContactHow to reach us
Email security@perionpayments.com with the affected hostname or public ID, steps, observed impact, and a safe proof. Do not email credentials, full payer data, raw provider payloads, or unredacted production evidence.
Start a security report →Response targets- Acknowledgement
- 1 business day
- Initial triage
- 3 business days
- Material update
- Every 5 business days
These are disclosure-process targets, not a bounty or a promise of remediation within a fixed period. Severity and safe deployment govern the correction plan.
Good-faith boundaryIn scope—and where to stop.
In scope
- Public API, hosted checkout, payment links, dashboard and console ingress
- Authentication, authorization, tenant isolation, webhook verification, and exposed sensitive data
- Published PerionPayments-owned origins listed on this site or in
security.txt
Stop and report
- Any access to another person's data or merchant environment
- Any action that could move money, send a payer prompt, alter evidence, or degrade service
- Any secret, provider credential, or production payload—retain only the minimum redacted proof
Out of scope
- Social engineering, physical intrusion, denial of service, spam, automated bulk scanning, and third-party systems
- Missing headers without exploitable impact, clickjacking on non-sensitive static pages, and version-only reports
- No paid bounty is offered until operational maturity supports one
Safe harbour is evidence-bound too.
PerionPayments will treat compliant, good-faith research as authorized within this policy and will not pursue action solely for that research. This does not authorize breaking law, touching third-party systems, retaining data, or continuing after a stop request. Formal legal review remains a pilot publication gate.
Read machine-readable security.txt →