Punchh · Vulnerability Disclosure
Punchh Vulnerability Disclosure
Vulnerability disclosure
Punchh runs a coordinated vulnerability disclosure program on Hackerone.
Gift CardsGuest EngagementLoyaltyMarketingMobileOffersOnline OrderingPAR TechnologyPoint-of-SaleRestaurantRestaurant TechnologyWebhook
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
probe: true
source: https://punchh.com/security/
provider: PAR Punchh
providerId: punchh
published: true
program:
platform: HackerOne
type: vulnerability disclosure / embedded submission form
submission_url: https://hackerone.com/79b77b5d-abe5-4210-9d1f-7b63465d1d4e/embedded_submissions/new
policy_page: https://punchh.com/security/
response_target: >-
"We'll get back to you as soon as we can, usually within 24 hours."
bounty: not stated
safe_harbour: not stated
security_txt:
published: false
probed:
- url: https://punchh.com/.well-known/security.txt
status: 404
- url: https://partech.com/.well-known/security.txt
status: 404
- url: https://developers.partech.com/.well-known/security.txt
status: 404
- url: https://api.punchh.com/.well-known/security.txt
status: 404
note: >-
The disclosure route is real but is a web page plus an embedded HackerOne form.
There is no RFC 9116 security.txt on any Punchh or PAR host, so an automated
scanner cannot discover it.
security_posture_published:
page: https://punchh.com/security/
claims:
- Data written to multiple disks, backed up daily, stored in multiple locations.
- HTTPS in transit; uploaded files encrypted at rest (project data/messages active in-database, not encrypted at rest).
- 2FA available on Punchh accounts; 2FA mandatory for the Punchh development team.
- Signed commits on GitHub for source deployment.
- AWS infrastructure; RDS across 3 Availability Zones; load-based autoscaling.
- Ruby on Rails with Redis and Sidekiq; dependencies kept current by a dedicated team.
- No card data stored on Punchh servers; card transactions handled by third-party PCI-compliant networks.
named_certifications: []
note: >-
No SOC 2, ISO 27001, HIPAA or FedRAMP claim, and no trust center. See
conformance/punchh-conformance.yml.
incident_notification:
source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
status_pages:
- https://status.punchh.com
- https://status.us-west.punchh.com
note: >-
Punchh publishes a five-step incident response and notification process for
partners, including publishing an advisory on its status pages and notifying
law enforcement where a criminal act is involved.
evidence:
- source: https://punchh.com/security/
kind: disclosure page
http_status: 200
keywords: [vulnerability, hackerone]
- source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
kind: partner security guidelines
http_status: 200
keywords: [security incident, notification, status page, rate limiting, bot management]
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/punchh-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.