Punchh · Vulnerability Disclosure

Punchh Vulnerability Disclosure

Vulnerability disclosure

Punchh runs a coordinated vulnerability disclosure program on Hackerone.

Gift CardsGuest EngagementLoyaltyMarketingMobileOffersOnline OrderingPAR TechnologyPoint-of-SaleRestaurantRestaurant TechnologyWebhook
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://punchh.com/security/
provider: PAR Punchh
providerId: punchh
published: true
program:
  platform: HackerOne
  type: vulnerability disclosure / embedded submission form
  submission_url: https://hackerone.com/79b77b5d-abe5-4210-9d1f-7b63465d1d4e/embedded_submissions/new
  policy_page: https://punchh.com/security/
  response_target: >-
    "We'll get back to you as soon as we can, usually within 24 hours."
  bounty: not stated
  safe_harbour: not stated
security_txt:
  published: false
  probed:
    - url: https://punchh.com/.well-known/security.txt
      status: 404
    - url: https://partech.com/.well-known/security.txt
      status: 404
    - url: https://developers.partech.com/.well-known/security.txt
      status: 404
    - url: https://api.punchh.com/.well-known/security.txt
      status: 404
  note: >-
    The disclosure route is real but is a web page plus an embedded HackerOne form.
    There is no RFC 9116 security.txt on any Punchh or PAR host, so an automated
    scanner cannot discover it.
security_posture_published:
  page: https://punchh.com/security/
  claims:
    - Data written to multiple disks, backed up daily, stored in multiple locations.
    - HTTPS in transit; uploaded files encrypted at rest (project data/messages active in-database, not encrypted at rest).
    - 2FA available on Punchh accounts; 2FA mandatory for the Punchh development team.
    - Signed commits on GitHub for source deployment.
    - AWS infrastructure; RDS across 3 Availability Zones; load-based autoscaling.
    - Ruby on Rails with Redis and Sidekiq; dependencies kept current by a dedicated team.
    - No card data stored on Punchh servers; card transactions handled by third-party PCI-compliant networks.
  named_certifications: []
  note: >-
    No SOC 2, ISO 27001, HIPAA or FedRAMP claim, and no trust center. See
    conformance/punchh-conformance.yml.
incident_notification:
  source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
  status_pages:
    - https://status.punchh.com
    - https://status.us-west.punchh.com
  note: >-
    Punchh publishes a five-step incident response and notification process for
    partners, including publishing an advisory on its status pages and notifying
    law enforcement where a criminal act is involved.
evidence:
  - source: https://punchh.com/security/
    kind: disclosure page
    http_status: 200
    keywords: [vulnerability, hackerone]
  - source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
    kind: partner security guidelines
    http_status: 200
    keywords: [security incident, notification, status page, rate limiting, bot management]

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/punchh-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.