Responsible disclosure

If you believe you have found a security vulnerability in PAID, we want to hear about it. This page defines what is in scope, how to report, the safe harbor we extend to good-faith researchers, and what you can expect from us. It supplements our public security model, which documents both what is implemented and what is honestly still on the roadmap.

Last updated: 2026-07-06

Scope

The following properties are in scope:

PropertyWhat it is
paid.trustfabric.aiMarketing site, merchant dashboard, and hosted checkout surfaces
api.trustfabric.aiProduction API (all endpoints served by this host, including /v1/*, /graphql, /sso/*, and /scim/v2/*)

Infrastructure operated by our sub-processors (Stripe, Plaid, Dwolla, ClearBank, Binance Pay, Circle, Sardine, Render) is out of scope here — report issues in those systems to the vendor's own disclosure program. If a vulnerability in our integration with a sub-processor exposes PAID data, that is in scope and we want the report.

How to report

Email [email protected]. This mailbox is the canonical intake channel for security reports. Please include:

One issue per report is easier for us to triage than a combined dump, but do not let that delay a report — send what you have.

Rules of engagement

Research qualifies as good-faith when it stays within these bounds:

Safe harbor

For security research conducted in good faith and within the rules of engagement above, we commit that we will not initiate legal action against you or refer you to law enforcement, and we consider such research authorized within the meaning of applicable anti-hacking and anti-circumvention law. If a third party pursues legal action against you for research that complied with this policy, we will make it known that your actions were authorized under this policy. This safe harbor does not extend to research that breaks the rules of engagement — in particular accessing or retaining other tenants' data beyond a minimal proof, or degrading the service for real users.

Out of scope

What to expect from us

SeverityCVSSRemediation target
Critical9.0 – 10.072 hours
High7.0 – 8.97 days
Medium4.0 – 6.930 days
Low0.1 – 3.990 days

We ask that you allow up to 90 days from your report before public disclosure. If we ship a fix sooner, we are happy to coordinate earlier publication. If we need longer (for example, a fix that depends on a sub-processor), we will tell you why and agree a revised date rather than go quiet.

Recognition

We do not currently operate a paid bug-bounty program, and this page does not promise one. Valid reports are recognized on request — we will credit you by name or handle once the issue is remediated, if you want the credit.

Machine-readable policy

An RFC 9116 security.txt is served at /.well-known/security.txt. It predates our domain migration to trustfabric.ai; where the two disagree, this page and [email protected] are canonical.

Related documents

Report a vulnerability: [email protected]
Privacy questions: [email protected]