CloudWalk · Vulnerability Disclosure

Cloudwalk Vulnerability Disclosure

Vulnerability disclosure

CloudWalk runs a named, public responsible-disclosure program covering its websites and APIs across both brands. The same policy page is published in two places — one scoped to *.cloudwalk.io and *.infinitepay.io, one scoped to *.cloudwalk.io and *.jim.com — with a single security contact and a one-business-day acknowledgement commitment. There is no bug bounty (no HackerOne / Bugcrowd / Intigriti program was found) and no /.well-known/security.txt.

CloudWalk runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsFinancial ServicesFintechCheckoutPoint of SaleAcquiringPixBrazilBankingWebhooksTap to Pay
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@cloudwalk.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://www.infinitepay.io/security
description: >-
  CloudWalk runs a named, public responsible-disclosure program covering its websites and
  APIs across both brands. The same policy page is published in two places — one scoped to
  *.cloudwalk.io and *.infinitepay.io, one scoped to *.cloudwalk.io and *.jim.com — with a
  single security contact and a one-business-day acknowledgement commitment. There is no bug
  bounty (no HackerOne / Bugcrowd / Intigriti program was found) and no /.well-known/security.txt.
policy:
- https://www.infinitepay.io/security
- https://www.jim.com/security-reporting
contact:
- security@cloudwalk.io
scope:
- '*.cloudwalk.io (websites and APIs)'
- '*.infinitepay.io (websites and APIs)'
- '*.jim.com (websites and APIs)'
- POS systems and applications
commitments:
  acknowledgement: within 1 business day
  process:
  - Confirm receipt of the report.
  - Investigate and evaluate the issue.
  - Respond with an estimated timeline for the fix.
  - Keep the reporter informed of progress.
  encrypted_communication: encouraged for sensitive information
  embargo: reporters asked not to disclose publicly until the issue is addressed
report_contents_requested:
- Detailed steps to reproduce.
- Expected and unintended results.
- Screenshots or logs.
- Browser and OS information.
bug_bounty:
  program: none found
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  rewards_published: false
  safe_harbor_published: false
security_txt:
  published: false
  paths_probed: ['/.well-known/security.txt', '/security.txt']
  hosts_probed: [cloudwalk.io, www.cloudwalk.io, infinitepay.io, www.infinitepay.io, api.infinitepay.io, api.checkout.infinitepay.io, jim.com, www.jim.com]
  result: 404 on every host/path
  note: >-
    A one-line RFC 9116 security.txt pointing at the existing policy would be the cheapest
    possible improvement here — the policy and contact already exist and are stable.
evidence:
- {source: 'https://www.infinitepay.io/security', kind: disclosure-policy, http_status: 200, keywords: [security researchers, responsible disclosure, 'security@cloudwalk.io', vulnerabilities, APIs]}
- {source: 'https://www.jim.com/security-reporting', kind: disclosure-policy, http_status: 200, keywords: [security reporting, responsible disclosure, 'security@cloudwalk.io']}
- {source: 'https://www.infinitepay.io/legal/politica-de-seguranca-cibernetica', kind: cyber-security-policy, http_status: 200}
x-evidence:
  fetched: '2026-08-01'
  probe_script: 'python3 all/0-working/probe-security-programs.py cloudwalk → vdp=none (its candidate paths, /security/responsible-disclosure etc., do not exist here); the policy was found by crawling the site footers instead and is recorded as searched.'