Paydeck is coming first to Bangkok, Phuket and Chiang Mai. Join the waitlist
Paydeck TH

Security and protection

Found something? Tell us.

We read every credible report, we answer, and we will not come after you for looking.

How to report

What to send us.

The more of this you include, the faster it gets fixed.

Where it is

The URL, endpoint or screen, and which environment you were on.

How to reproduce it

Steps, in order, that we can follow. A short recording is welcome; a proof-of-concept is better than a description.

What it lets someone do

Your read on the impact. We would rather have your honest assessment than a severity rating.

How to credit you

A name or handle if you would like acknowledgement, or tell us you would rather stay anonymous.

Scope.

In scopeOut of scope
Systemspaydeck.th and its subdomains, the Paydeck iOS and Android apps, and our public APIsThird-party services we use, unless the issue is in how we configured them
Issue typesAuthentication and authorisation flaws, payment logic errors, data exposure, injection, account takeoverMissing best-practice headers with no demonstrated impact, rate-limit noise, self-XSS, outdated library versions with no working exploit
ReportsA working reproduction against your own test accountAutomated scanner output pasted without triage, and anything touching another person's data

Ground rules

Testing we can defend.

Use your own account

Never access, modify or store another person's data. Stop as soon as you can prove the issue.

Do not degrade the service

No denial of service, no load testing, no spam to real users, no social engineering of our staff.

Give us time

Tell us privately first and allow a reasonable window before publishing anything.

What we promise in return.

We acknowledge

Within 3 business days

A human replies confirming we have your report.

We triage and tell you

Within 10 business days

You get our assessment, including if we disagree, and why.

We fix and credit

Severity-dependent

You hear when it ships, and you are credited if you want to be.

Safe harbour: if you follow these rules, act in good faith and report to us privately, we will not pursue legal action against you for your research.

One thing we ask you never to send

Do not include real card numbers, identity documents, bank account numbers or anyone else's personal data in a report: not as evidence, not as an attachment. Describe what you could reach and we will verify it ourselves. Redact everything else.

Paydeck does not currently run a paid bounty programme. We credit researchers publicly with their consent, and we answer every credible report.

security@paydeck.th

Encrypted reports welcome. Please include steps to reproduce.

Latest writings

Practical notes for making life in Thailand easier.

View all posts