Skip to content

Security

Responsible disclosure

How to report security vulnerabilities affecting aqpay.co and related AQPAY technical systems.

Purpose

AQPAY LTD welcomes good-faith reports of security issues that may affect the public technical website or authorised platform components under AQPAY control.

Authorised testing scope

  • Public pages on aqpay.co
  • Publicly reachable documentation and status interfaces
  • Security issues in published client-side assets belonging to this site

Prohibited testing

  • Accessing or attempting to access other customers' data
  • Denial-of-service or resource exhaustion attacks
  • Social engineering of employees, partners or customers
  • Physical attacks against offices, staff or infrastructure
  • Malware distribution or destructive exploitation
  • Testing payment processing systems without written authorisation
  • Circumvention of fraud, risk or authentication controls in live traffic

How to report

Use the security contact issued to authorised technical partners, or your AQPAY technical account contact, until a dedicated public mailbox is confirmed and monitored. Reports should include:

  • Affected URL or component
  • Description of the issue and potential impact
  • Steps to reproduce
  • Proof-of-concept limited to demonstrating the issue
  • Your contact details for acknowledgement

Expectations

  • We aim to acknowledge valid reports once a monitored channel is active.
  • Please allow reasonable time for investigation before public disclosure.
  • Do not include real cardholder data or live secrets in reports.
  • Keep vulnerability details confidential until remediation is complete where practical.

Safe harbour

AQPAY intends to treat good-faith research conducted within this policy as authorised. This wording is subject to legal review and does not permit activity outside the stated scope. This page does not create a public bug bounty or reward programme.