SkullPay
Sign in Get started

Security

How the platform is built, and how to report a security problem.

Architecture in brief

Responsible disclosure

We welcome reports from security researchers. Email security@skullpay.co with enough detail to reproduce the issue. We will acknowledge within two business days, keep you informed, and credit you if you wish once a fix ships. Machine-readable contact details live at /.well-known/security.txt.

Please: test only against accounts you own (staging environments are ideal), never against merchants' live stores or real payers; do not access, modify or exfiltrate data that is not yours; avoid denial-of-service testing; give us a reasonable time to fix before public disclosure.

In scope: skullpay.co, portal.skullpay.co, pay.skullpay.co, api.skullpay.co, the WordPress plugin and the SDK. Out of scope: third-party providers, social engineering, physical attacks, and findings that require a compromised device or browser.