PayEngine · Vulnerability Disclosure

Payengine Vulnerability Disclosure

Vulnerability disclosure

PayEngine runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

PaymentsEmbedded PaymentsPayment FacilitationMerchant OnboardingPayment GatewayFinancial-ServicesACHTokenizationWebhookFintechCompany
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
channelgeneral support mailbox
Contact
dedicated_security_addressfalse
Contact
emailsupport@payengine.co
Contact
noteThe security page names support@payengine.co as the security contact. It is the same address used for billing and product support, not a dedicated security alias.

Source

Vulnerability Disclosure

payengine-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.payengine.co/security
name: PayEngine vulnerability disclosure posture
summary: >-
  PayEngine publishes a security overview page and names a security contact address, but
  it operates no formal vulnerability disclosure program. There is no responsible- or
  coordinated-disclosure policy, no safe-harbour statement, no bug bounty on HackerOne,
  Bugcrowd or Intigriti, and no security.txt on any host. A researcher who finds a flaw
  in a PCI DSS Level 1 payments platform has one route: the general support mailbox.
security_page:
  url: https://www.payengine.co/security
  status: 200
  checked: '2026-08-26'
  published: true
contact:
  email: support@payengine.co
  channel: general support mailbox
  dedicated_security_address: false
  note: >-
    The security page names support@payengine.co as the security contact. It is the same
    address used for billing and product support, not a dedicated security alias.
policy:
  published: false
  safe_harbour: false
  response_sla: false
  scope_statement: false
  preferred_languages: null
bug_bounty:
  program: none
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  result: no PayEngine program found
security_txt:
  served: false
  hosts_probed:
  - host: www.payengine.co
    status: 404
  - host: api.payengine.co
    status: 400
  - host: docs.payengine.co
    status: 404
  - host: status.payengine.co
    status: 404
  - host: console.payengine.co
    status: 200
    result: SPA HTML shell, not a security.txt document
  see: well-known/payengine-well-known.yml
published_practices:
  note: Claims made on the security page, recorded as claims, not verified by us.
  claims:
  - Full compliance with the Payment Card Industry Data Security Standard (PCI DSS)
  - All data transmitted to and from PayEngine is encrypted using industry-standard protocols
  - 24/7 monitoring for fraud detection
  - Regular security audits
  - An incident response plan with a stated commitment to transparency
  - Employee security training and access controls
  independently_verifiable:
  - claim: PCI DSS Level 1 Service Provider
    verification: >-
      Listed in the Visa Global Registry of Service Providers as Platform Factory, Inc.
      (spId 4019). See conformance/payengine-conformance.yml.
trust_center:
  published: false
  note: >-
    No trust.payengine.co, no certification portal, and no downloadable SOC 2 / ISO 27001
    report or attestation request flow. PCI DSS is the only named certification, and
    documentation of it is obtained through the sales/onboarding process - the docs
    describe forwarding a token-migration request to PayEngine so it can supply PCI L1
    evidence to a prior provider.
gaps:
- No vulnerability disclosure policy of any kind.
- No security.txt (RFC 9116) on any host.
- No dedicated security contact address.
- No SOC 2 or ISO 27001 certification named anywhere on the public site.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/payengine-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.