security@perionpayments.com
Send the affected hostname or public ID, steps, observed impact, and a safe proof. Do not email credentials, full payer data, raw provider payloads, or unredacted production evidence.
Start a security report →We welcome good-faith reports that help protect merchants and payers. Minimise data, stop before money or availability is at risk, and give us a reproducible path.
Send the affected hostname or public ID, steps, observed impact, and a safe proof. Do not email credentials, full payer data, raw provider payloads, or unredacted production evidence.
Start a security report →These are disclosure-process targets, not a bounty or a promise of remediation within a fixed period. Severity and safe deployment govern the correction plan.
PerionPayments will treat compliant, good-faith research as authorized within this policy and will not pursue action solely for that research. This does not authorize breaking law, touching third-party systems, retaining data, or continuing after a stop request. Formal legal review remains a pilot publication gate.
Read machine-readable security.txt →