Vulnerability Disclosure Policy
How to report a security issue, and what we commit to in return.
← Legal AgreementsLast updated: Aug 30, 2026
Scope
This policy covers payvioapp.com, support.payvioapp.com, and the Payvio mobile app. It does not cover social engineering of our staff, physical attacks on our offices, or denial-of-service testing — please don't attempt these.
How to report
Email [email protected] with clear reproduction steps, the impact you believe it has, and any proof-of-concept material. Encrypt sensitive findings if you're comfortable doing so; ask us for a key if needed.
Our commitment
We acknowledge every report within one business day, and we'll keep you updated as we investigate and fix the issue. We do not pursue legal action against researchers who report privately, in good faith, and give us reasonable time to remediate before any public disclosure.
What not to do
Please don't access, modify, or delete data that isn't yours while testing, and stop as soon as you've confirmed a vulnerability exists rather than exploring further. Don't publicly disclose an issue before we've had a chance to fix it.
Account-specific issues
If you have a concern about your own account — a compromised login, or a transfer you didn't authorize — contact support directly instead. It moves faster than a security report and doesn't need this process.