How to report
Email contact@ispbillingpay.com with a concise description, affected endpoint, safe reproduction steps and the potential impact. Provide timestamps and synthetic references where possible. Do not include live secrets, full payment messages or customer records in the initial email.
Testing boundaries
Use your own sandbox or systems you are explicitly authorised to test. Do not access another merchant’s data, disrupt service, alter live payments, attempt social engineering or persist access. Stop if a test exposes unexpected personal information and report the minimum evidence needed.
Coordination
Give the operator a reasonable opportunity to investigate before public disclosure. Acknowledgement and remediation schedules need to be agreed for each report. This page does not promise a bounty, a response deadline or legal safe harbour.
If a credential is exposed
Rotate or revoke it immediately through the relevant account controls and inspect related activity. Contact the operator if access is lost. Never publish a credential to demonstrate the issue.
KEEP EXPLORING