Legal

Vulnerability Disclosure Policy

How to report a security issue, and what we commit to in return.

← Legal Agreements

Last updated: Aug 30, 2026

Scope

This policy covers payvioapp.com, support.payvioapp.com, and the Payvio mobile app. It does not cover social engineering of our staff, physical attacks on our offices, or denial-of-service testing — please don't attempt these.

How to report

Email [email protected] with clear reproduction steps, the impact you believe it has, and any proof-of-concept material. Encrypt sensitive findings if you're comfortable doing so; ask us for a key if needed.

Our commitment

We acknowledge every report within one business day, and we'll keep you updated as we investigate and fix the issue. We do not pursue legal action against researchers who report privately, in good faith, and give us reasonable time to remediate before any public disclosure.

What not to do

Please don't access, modify, or delete data that isn't yours while testing, and stop as soon as you've confirmed a vulnerability exists rather than exploring further. Don't publicly disclose an issue before we've had a chance to fix it.

Account-specific issues

If you have a concern about your own account — a compromised login, or a transfer you didn't authorize — contact support directly instead. It moves faster than a security report and doesn't need this process.