PayMongo · Vulnerability Disclosure

Paymongo Vulnerability Disclosure

Vulnerability disclosure

PayMongo publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

PaymentsFinTechPhilippinesSoutheast AsiaGCashE-WalletCard Payments
Program: security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@paymongo.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-17'
method: searched
probe: true
source: https://docs.paymongo.com/docs/keeping-payments-secure
securityTxt: false
securityTxtProbe:
  url: https://paymongo.com/.well-known/security.txt
  status: 404
contact:
- mailto:security@paymongo.com
bugBounty:
  public_program: false
  note: No public bug-bounty or formal published responsible-disclosure policy was found at probe time.
evidence:
- source: https://paymongo.com/.well-known/security.txt
  kind: security.txt (live probe)
  result: HTTP 404 - no security.txt published
- source: https://docs.paymongo.com/docs/keeping-payments-secure
  kind: documentation
  note: Describes ongoing third-party vulnerability scanning and penetration testing.
notes: >-
  As of the probe date PayMongo does not publish a /.well-known/security.txt
  (HTTP 404) and no public bug-bounty program was found. PayMongo states its
  systems undergo regular third-party vulnerability scanning and penetration
  testing as part of PCI DSS Level 1 compliance. Security concerns are best
  routed to security@paymongo.com or support@paymongo.com; verify the correct
  disclosure channel with PayMongo directly, as no formal published policy was
  located.