How to report a security issue
Please submit suspected vulnerabilities, exposed credentials, account-takeover concerns, abuse reports, or other security issues through our public contact flow and select the security report request type.
Include enough detail for us to reproduce or triage the issue, such as the affected URL or workflow, steps to reproduce, timestamps, screenshots where appropriate, and the impact you observed.
Good-faith testing expectations
- avoid privacy violations, service disruption, destructive testing, or attempts to access another person’s data
- do not exploit a finding beyond what is reasonably necessary to demonstrate the issue
- do not use social engineering, spam, physical intrusion, or denial-of-service activity
- give us a reasonable chance to investigate and remediate before public disclosure
What comPayr will do
We will review good-faith reports, route them for internal triage, and use the information to validate severity, fix issues, and improve safeguards where needed.
We may request clarification if a report is incomplete, and we may decline to act on reports that are abusive, duplicative, outside our control, or based on unsupported testing methods.
Current scope limits
This page is a practical launch-stage disclosure channel, not a bug-bounty program or standing promise of payment.
Only systems, workflows, and assets operated by comPayr are within scope. Third-party services are governed by their own programs and reporting paths.
