Section 01
Reporting a vulnerability
Where to send it, what to include, and our commitment not to pursue good-faith research.
How we protect accounts and payments, and how to report a vulnerability to us.
Where to send it, what to include, and our commitment not to pursue good-faith research.
Which apps, domains and APIs are in scope, and what is out of scope.
Acknowledgement, triage and fix targets.
Phone verification, session handling, and what we will never ask you for.
How wallet balances and card top-ups are handled, and the single-use QR design.
Encryption in transit and at rest, access control and audit logging.
Researchers who have reported responsibly.