Punchh · Vulnerability Disclosure

Punchh Vulnerability Disclosure

Vulnerability disclosure

Punchh runs a coordinated vulnerability disclosure program on Hackerone.

Gift CardsGuest EngagementLoyaltyMarketingMobileOffersOnline OrderingPAR TechnologyPoint-of-SaleRestaurantRestaurant TechnologyWebhook
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://punchh.com/security/
provider: PAR Punchh
providerId: punchh
published: true
program:
  platform: HackerOne
  type: vulnerability disclosure / embedded submission form
  submission_url: https://hackerone.com/79b77b5d-abe5-4210-9d1f-7b63465d1d4e/embedded_submissions/new
  policy_page: https://punchh.com/security/
  response_target: >-
    "We'll get back to you as soon as we can, usually within 24 hours."
  bounty: not stated
  safe_harbour: not stated
security_txt:
  published: false
  probed:
    - url: https://punchh.com/.well-known/security.txt
      status: 404
    - url: https://partech.com/.well-known/security.txt
      status: 404
    - url: https://developers.partech.com/.well-known/security.txt
      status: 404
    - url: https://api.punchh.com/.well-known/security.txt
      status: 404
  note: >-
    The disclosure route is real but is a web page plus an embedded HackerOne form.
    There is no RFC 9116 security.txt on any Punchh or PAR host, so an automated
    scanner cannot discover it.
security_posture_published:
  page: https://punchh.com/security/
  claims:
    - Data written to multiple disks, backed up daily, stored in multiple locations.
    - HTTPS in transit; uploaded files encrypted at rest (project data/messages active in-database, not encrypted at rest).
    - 2FA available on Punchh accounts; 2FA mandatory for the Punchh development team.
    - Signed commits on GitHub for source deployment.
    - AWS infrastructure; RDS across 3 Availability Zones; load-based autoscaling.
    - Ruby on Rails with Redis and Sidekiq; dependencies kept current by a dedicated team.
    - No card data stored on Punchh servers; card transactions handled by third-party PCI-compliant networks.
  named_certifications: []
  note: >-
    No SOC 2, ISO 27001, HIPAA or FedRAMP claim, and no trust center. See
    conformance/punchh-conformance.yml.
incident_notification:
  source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
  status_pages:
    - https://status.punchh.com
    - https://status.us-west.punchh.com
  note: >-
    Punchh publishes a five-step incident response and notification process for
    partners, including publishing an advisory on its status pages and notifying
    law enforcement where a criminal act is involved.
evidence:
  - source: https://punchh.com/security/
    kind: disclosure page
    http_status: 200
    keywords: [vulnerability, hackerone]
  - source: https://developers.partech.com/docs/dev-portal-developer-resources/punchh-api-security-guidelines
    kind: partner security guidelines
    http_status: 200
    keywords: [security incident, notification, status page, rate limiting, bot management]