Mesh Payments · Vulnerability Disclosure

Mesh Payments Vulnerability Disclosure

Vulnerability disclosure

Mesh Payments publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyPaymentsSpend ManagementExpense ManagementCorporate CardsTravelAccounts PayableFintechCard IssuingAccounting Automation
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@meshpayments.com
Contact
privacy@meshpayments.com

Source

Vulnerability Disclosure

mesh-payments-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-04'
method: searched
probe: true
probe_result: the mechanical probe found nothing because Mesh publishes no /.well-known/security.txt
  and hosts its policy at a non-standard path; the policy below was found and fetched
  by hand.
policy:
- https://meshpayments.com/vulnerability-disclosure-policy/
contact:
- security@meshpayments.com
- privacy@meshpayments.com
bug_bounty:
  program: false
  note: no structured bounty program. The policy states rewards are discretionary -
    "The decision to pay a reward is entirely at our discretion."
safe_harbor: true
safe_harbor_text: Mesh Payments pledges not to initiate any legal action against researchers
  if they adhere to the guidelines outlined in our Vulnerability Disclosure Policy.
scope:
  in_scope: All Mesh Payments services and products.
  excluded_activities:
  - social engineering
  - data destruction
  - denial of service
  - unauthorized use of assets
  - malware distribution
  excluded_findings:
  - automated scanner output without a proof of concept
  - vulnerabilities in third-party services
  accepted_classes:
  - server misconfiguration
  - injection
  - cross-site scripting
  - authentication and access control flaws
  - cryptographic weaknesses
  - mobile application security issues
  eligibility_restrictions:
  - under 13 (COPPA)
  - residents of US-sanctioned countries
coordinated_disclosure: researchers are asked to withhold public disclosure until Mesh
  has researched, responded to and addressed the report
gaps:
- No /.well-known/security.txt (RFC 9116) is served on meshpayments.com, api.meshpayments.com,
  kb.meshpayments.com or app.meshpayments.com. Publishing one that points Policy at
  https://meshpayments.com/vulnerability-disclosure-policy/ and Contact at mailto:security@meshpayments.com
  would make an existing, well-written program machine-discoverable.
evidence:
- source: https://meshpayments.com/vulnerability-disclosure-policy/
  kind: disclosure-policy-page
  http_status: 200
- source: https://meshpayments.com/security-is-our-priority/
  kind: security-page
  http_status: 200
- source: https://meshpayments.com/.well-known/security.txt
  kind: security.txt
  http_status: 404
x-evidence:
  fetched: '2026-08-04'