Our Promise
OnPay is a PCI-DSS certified payment gateway, and protecting the cardholder and personal data we process is of the highest importance to us. We believe that strong security is fundamental to the trust our merchants and their customers place in us.
No matter how much effort we put into securing our systems, vulnerabilities can still exist. If you discover one, we want to hear from you so we can address it as quickly as possible. We value the work of the security research community and welcome reports made in good faith.
Guidelines
We are interested in your findings, they help us improve. To protect our merchants, their customers and the wider payment ecosystem, we ask all security researchers and practitioners to:
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or modification of data during testing.
- Only access, store or interact with the minimum amount of data necessary to demonstrate a vulnerability. Never access, download, store or transmit real cardholder data (card numbers, CVV/CVC, expiry dates), personal data belonging to merchants or their customers, or any sensitive authentication data.
- Use OnPay's test mode and test cards wherever possible instead of live transactions. Do not initiate, capture, refund or otherwise interfere with real payments or the accounts of real merchants.
- Perform research only within the scope set out below.
- Use the reporting channel identified below to disclose vulnerability information to us.
- Keep any vulnerability you discover confidential between you and us until we have had a reasonable opportunity to resolve it.
If you follow these guidelines when reporting an issue, we commit to:
- Not pursue or support any legal action related to your good-faith research (see Safe Harbour below).
- Acknowledge receipt of your report within 7 business days.
- Provide an initial assessment and an indication of expected resolution timeline, and keep you updated on our progress.
- Work with you to understand and resolve the issue as quickly as possible.
- Handle your report in strict confidence and not share your personal details with third parties without your permission.
- Credit you as the discoverer in any public disclosure relating to the issue, unless you prefer to remain anonymous.
Scope
The following are in scope:
- https://onpay.io and the OnPay control panel / dashboard
- The OnPay API and official OnPay integrations and plugins published by us
In the interest of our merchants, their customers, system preservation and the wider internet community, the following are out of scope and we ask you to refrain from them:
- Any tests on services hosted or operated by third-party providers (e.g. acquirers, card schemes, wallet providers such as MobilePay, Apple Pay or Google Pay, or banking partners).
- Tests of applications, integrations or systems not under OnPay's control, including merchant webshops.
- Attacks against, or use of, the accounts, data or transactions of real merchants or their customers.
- Physical testing (e.g. office access, tailgating).
- Social engineering (e.g. phishing, vishing) of OnPay staff, merchants or customers.
- Network-level Denial of Service (DoS/DDoS) testing.
- Spam, or automated/volumetric testing that could degrade service availability.
- Findings derived solely from automated scanners without a demonstrated, exploitable impact.
Safe Harbour
Openness and honesty are essential, while at the same time we must respect each other's work. Some testing activities could be considered unlawful depending on the jurisdiction of the service and of the researcher.
We provide assurance that researchers who act in good faith, follow the guidelines set out in this statement, and wish to work constructively with us, will not be unduly penalised. We will not pursue or support legal action against you for security research and disclosure conducted in accordance with this statement. If legal action is initiated by a third party against you for activities conducted in line with this statement, we will make this position known.
This statement does not give you permission to act in any manner that is inconsistent with the law, or that could cause OnPay or its partners to be in breach of any legal obligations.
How to Report
If you believe you have found a vulnerability in one of our platforms or services, we want to hear from you.
Where possible, please encrypt sensitive findings using our PGP key, referenced in our security.txt file, to ensure the information cannot fall into the wrong hands.
When submitting, please include:
- A clear description of the vulnerability.
- The location (URL, endpoint, IP, parameter or component affected).
- The potential impact and how it could be exploited.
- Detailed, reproducible steps (proof-of-concept scripts, requests, screenshots or short screen recordings are all helpful).
- A valid return address so we can contact you with questions and to acknowledge your work.
Please submit your report in English or Danish.
Thank you for helping us keep OnPay secure.