If you believe you have found a security vulnerability in PAID, we want to hear about it. This page defines what is in scope, how to report, the safe harbor we extend to good-faith researchers, and what you can expect from us. It supplements our public security model, which documents both what is implemented and what is honestly still on the roadmap.
Last updated: 2026-07-06
The following properties are in scope:
| Property | What it is |
|---|---|
paid.trustfabric.ai | Marketing site, merchant dashboard, and hosted checkout surfaces |
api.trustfabric.ai | Production API (all endpoints served by this host, including /v1/*, /graphql, /sso/*, and /scim/v2/*) |
Infrastructure operated by our sub-processors (Stripe, Plaid, Dwolla, ClearBank, Binance Pay, Circle, Sardine, Render) is out of scope here — report issues in those systems to the vendor's own disclosure program. If a vulnerability in our integration with a sub-processor exposes PAID data, that is in scope and we want the report.
Email [email protected]. This mailbox is the canonical intake channel for security reports. Please include:
api.trustfabric.ai + the request path.One issue per report is easier for us to triage than a combined dump, but do not let that delay a report — send what you have.
Research qualifies as good-faith when it stays within these bounds:
sk_test_…) work against the live API — see the quickstart — so there is no reason to touch live-mode money paths.For security research conducted in good faith and within the rules of engagement above, we commit that we will not initiate legal action against you or refer you to law enforcement, and we consider such research authorized within the meaning of applicable anti-hacking and anti-circumvention law. If a third party pursues legal action against you for research that complied with this policy, we will make it known that your actions were authorized under this policy. This safe harbor does not extend to research that breaks the rules of engagement — in particular accessing or retaining other tenants' data beyond a minimal proof, or degrading the service for real users.
| Severity | CVSS | Remediation target |
|---|---|---|
| Critical | 9.0 – 10.0 | 72 hours |
| High | 7.0 – 8.9 | 7 days |
| Medium | 4.0 – 6.9 | 30 days |
| Low | 0.1 – 3.9 | 90 days |
We ask that you allow up to 90 days from your report before public disclosure. If we ship a fix sooner, we are happy to coordinate earlier publication. If we need longer (for example, a fix that depends on a sub-processor), we will tell you why and agree a revised date rather than go quiet.
We do not currently operate a paid bug-bounty program, and this page does not promise one. Valid reports are recognized on request — we will credit you by name or handle once the issue is remediated, if you want the credit.
An RFC 9116 security.txt is served at /.well-known/security.txt. It
predates our domain migration to trustfabric.ai; where the two
disagree, this page and [email protected] are canonical.
Report a vulnerability: [email protected]
Privacy questions: [email protected]