Purpose
AQPAY LTD welcomes good-faith reports of security issues that may affect the public technical website or authorised platform components under AQPAY control.
Authorised testing scope
- Public pages on aqpay.co
- Publicly reachable documentation and status interfaces
- Security issues in published client-side assets belonging to this site
Prohibited testing
- Accessing or attempting to access other customers' data
- Denial-of-service or resource exhaustion attacks
- Social engineering of employees, partners or customers
- Physical attacks against offices, staff or infrastructure
- Malware distribution or destructive exploitation
- Testing payment processing systems without written authorisation
- Circumvention of fraud, risk or authentication controls in live traffic
How to report
Use the security contact issued to authorised technical partners, or your AQPAY technical account contact, until a dedicated public mailbox is confirmed and monitored. Reports should include:
- Affected URL or component
- Description of the issue and potential impact
- Steps to reproduce
- Proof-of-concept limited to demonstrating the issue
- Your contact details for acknowledgement
Expectations
- We aim to acknowledge valid reports once a monitored channel is active.
- Please allow reasonable time for investigation before public disclosure.
- Do not include real cardholder data or live secrets in reports.
- Keep vulnerability details confidential until remediation is complete where practical.
Safe harbour
AQPAY intends to treat good-faith research conducted within this policy as authorised. This wording is subject to legal review and does not permit activity outside the stated scope. This page does not create a public bug bounty or reward programme.