paydock logo on transparent background
  • Solutions

    Solutions

    For Banks

    For Merchants

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    post
    page
    • Expand Market Share
    • Elevate Merchant Experience
    • Offer the Latest Payment Technology
    • Rocket Launch New Merchant Services
    • Minimising Payment Tech Risk
    • Ever Fresh Payment Experiences
    • Deep Security and Stability Uplift
    • Reporting and Reconciliation Fixes
  • Our Platform

    Our Platform​

    Paydock

    Quick Contact

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    post
    page
    • Our Platform
    • Features
    • For Banks
    • For Merchants
    • Our Platform
    • Features
    • Contact Support
    • Our Helpdesk
    • Contact Us
  • Developers

    Developers

    Paydock

    Resources

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    post
    page
    • Status Page
    • Documentation
    • Support
    • Our Helpdesk
    • Release Notes
    • Changelog
    • GitHub
    • Boilerplates
    • NPM
    • Responsible Disclosure
  • About

    About

    Paydock

    Newsroom

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    post
    page
    • Values
    • Careers at Paydock
    • Our Team
    • About Us - Our History
    • Newsroom
    • Contact Us
    • Blogs
    • Press Releases
    • Podcasts
  • Search

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    post
    page

    Most Searched

    • Features
    • Contact Us
    • Banks
    • Merchants
Get Started
Log In

Responsible Disclosure

NOTE: It is important to read the following section prior to test and/or report a vulnerability on any of the PayDock software solutions.

 

As every piece of code written by a human being is prone to issues, we are not exempt. We try our best to reduce the presence of such security bugs in our technologies but we also know that our resources are limited and acknowledge there are others intelligent individuals out there. Therefore, we are open to hear from them and their willingness to help to secure the digital era.

In order to achieve such a big but amazing goal, here is the information you need to be aware of when getting in contact with us.

 

Eligibility

In order for PayDock to consider your submission the following criteria will apply:

  1. Violation of any law that applies to regions involved in the submission.
  2. If you are considered to be a minor in either of the countries involved in the submission, you must get parent’s or minder’s approval.
  3. The only compensation provided is through public recognition so please refrain from other types.

Scope

 

URLs

 

 

The following links cover our web presence

  • api.paydock.com
  • app.paydock.com
  • *.paydock.com

The following software is also covered by this policy:

  • Officially supported SDKs

Regarding the vulnerabilities that are in scope, these may include but are not limited to the following:

  • Server-side or remote code execution (RCE)
  • Authentication or authorization flaws, including insecure direct object references and authentication bypass
  • Injection vulnerabilities, including SQL and XML injection
  • Directory traversal
  • Significant security misconfiguration with a verifiable vulnerability
 

 

The following vulnerabilities will be also considered for web sites:

  • Disclosure of sensitive or personally identifiable information
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF) for sensitive functions in a privileged context

Out of scope

 

Any software in the form of application, either web or mobile, and/or services that are not described in the above section are considered to be outside of the scope of this policy. Therefore, any activity identified on them will be rejected and considered a breach of policy, treated as an illegal conduct, and reported to the relevant parties for prosecution.

 

How to contact us

In order for us to receive and accept your reports you need to use the following information

 

Email

Send any communications to [email protected] with all the relevant information regarding the vulnerability identified. Remember that all the information presented is used for verification purposes so the more detailed you provide the better for us to consider your report.

 

The following considerations should be in place for all parties involved in the disclosure:

  • Respect merchant’s and their customers’ privacy.
  • Be transparent and open

No other forms of reporting will be considered under this policy and any public interaction over other channels (e.g. Facebook, twitter, etc.) will not be considered formal and tolerated.

 

You can encrypt communications to [email protected] with our PGP Key.

 

Terms and conditions

An individual participating in the responsible disclosure process is voluntarily and any report will be considered for review. No monetary recognition will be given to the reporters for their voluntary work, but we will be happy to provide public recognition for their hard work and invaluable input.

white paydock logo on transparent background
👋 we are hiring self-motivated people to join our team

Solutions

  • For Banks
  • For Merchants

Our Platform

  • Our Platform
  • Features

Developers

  • Status Page
  • Documentation
  • Support
  • Helpdesk
  • Release Notes
  • Changelog

About

  • Values
  • Careers at Paydock
  • Team
  • About Us - Our History
  • Newsroom
  • Contact Us
  • Solutions
    • For Banks
      • Expand Market Share
      • Elevate Merchant Experience
      • Offer the Latest Payment Technology
      • Rocket Launch New Merchant Services
    • For Merchants
      • Eliminating Payment Tech Risk
      • Ever Fresh Payment Experiences
      • Deep Security and Stability Uplift
      • Reporting and Reconciliation Fixes
      • Be A Master Merchant
  • Our Platform
    • Features
  • Developers
    • Status page
    • Paydock Documentation
    • Paydock Support
    • Our Helpdesk
  • About
    • Our Values
    • Careers
    • Our Team
    • About Us
    • Newsroom
    • Contact Us
Black Linkedin Logo On Transparent Background Black X Logo On Transparent Background Black Youtube Logo On Transparent Background Black Instagram Logo On Transparent Background

Paydock Holdings Pty Limited
L40,
2 Park Street,
Sydney,
NSW 2000,
Australia

 

 

Paydock Ltd
Arquen House,
4-6 Spicer Street,
St. Albans,
Hertfordshire,
England,
AL3 4PQ

Copyright © Paydock 2023. All Rights Reserved | Privacy Policy | Website Terms of Use 

Manage Cookie Consent
We collect cookies to analyse our website traffic and performance.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}