← Resource centre

POLICIES

Report a security concern

Help us understand a vulnerability without exposing other customers.

Policy version · 21 September 2026. Read together with the service terms and your applicable written agreement.
01

How to report

Email contact@ispbillingpay.com with a concise description, affected endpoint, safe reproduction steps and the potential impact. Provide timestamps and synthetic references where possible. Do not include live secrets, full payment messages or customer records in the initial email.

02

Testing boundaries

Use your own sandbox or systems you are explicitly authorised to test. Do not access another merchant’s data, disrupt service, alter live payments, attempt social engineering or persist access. Stop if a test exposes unexpected personal information and report the minimum evidence needed.

03

Coordination

Give the operator a reasonable opportunity to investigate before public disclosure. Acknowledgement and remediation schedules need to be agreed for each report. This page does not promise a bounty, a response deadline or legal safe harbour.

04

If a credential is exposed

Rotate or revoke it immediately through the relevant account controls and inspect related activity. Contact the operator if access is lost. Never publish a credential to demonstrate the issue.

KEEP EXPLORING

Your next connection starts here.